Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 59895

Summary: net-misc/cfengine-2.1.8 fixes RSA Authentication Heap Corruption
Product: Gentoo Security Reporter: Sune Kloppenborg Jeppesen (RETIRED) <jaervosz>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: critical    
Priority: High    
Version: unspecified   
Hardware: All   
OS: All   
URL: http://www.securityfocus.com/archive/1/371257
Whiteboard: B0 [ glsa ]
Package list:
Runtime testing required: ---

Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-08-09 13:50:20 UTC
Two vulnerabilities were found in cfservd, a daemon which acts as both a file server and a remote cfagent executor. This daemon authenticates requests from the network and processes them. If exploited, the first vulnerability allows an attacker to execute arbitrary code with those privileges of root. The second vulnerability allows an attacker to crash the server, denying service to further requests.
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-08-09 13:58:44 UTC
Kurt this is your baby.
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-08-09 14:30:04 UTC
Bumping to 2.1.9 seems to work.

Security : GLSA drafted please review.
Comment 3 Kurt Lieber (RETIRED) gentoo-dev 2004-08-09 17:16:08 UTC
Another URL that might be useful in drafting the GLSA:

http://www.coresecurity.com/common/showdoc.php?idx=387&idxseccion=10

Committed 2.1.9 directly to stable on x86 after testing it on my machine.  As soon as sparc stables it, we're good to go.
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-08-10 03:30:34 UTC
Woops Kurt didn't CC sparc.

sparc please mark stable ASAP so the GLSA can go out.
Comment 5 Jason Wever (RETIRED) gentoo-dev 2004-08-10 06:34:50 UTC
sparc me amadeus
Comment 6 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-08-12 09:13:50 UTC
woops closing for Kurt.

GLSA 200408-08