Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 353955 - <net-misc/stunnel-4.35: file descriptor leaks
Summary: <net-misc/stunnel-4.35: file descriptor leaks
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.stunnel.org/?page=sdf_Chan...
Whiteboard: B3 [glsa?]
Keywords:
: 349074 (view as bug list)
Depends on:
Blocks: 344117
  Show dependency tree
 
Reported: 2011-02-07 12:12 UTC by Stefan Behte (RETIRED)
Modified: 2011-10-08 21:10 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
stunnel-4.35-libwrap.patch (stunnel-4.35-libwrap.patch,376 bytes, patch)
2011-02-07 16:00 UTC, Stefan Behte (RETIRED)
no flags Details | Diff
stunnel-4.35-xforwarded-for.diff (stunnel-4.35-xforwarded-for.diff,10.85 KB, patch)
2011-02-07 16:37 UTC, Stefan Behte (RETIRED)
no flags Details | Diff
stunnel-4.34-listen-queue.diff (stunnel-4.34-listen-queue.diff,2.17 KB, patch)
2011-02-07 16:40 UTC, Stefan Behte (RETIRED)
no flags Details | Diff
stunnel-4.35.ebuild (stunnel-4.35.ebuild,2.28 KB, text/plain)
2011-02-07 16:45 UTC, Stefan Behte (RETIRED)
no flags Details
stunnel-4.35.ebuild (stunnel-4.35.ebuild,2.26 KB, text/plain)
2011-02-07 16:51 UTC, Stefan Behte (RETIRED)
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2011-02-07 12:12:26 UTC
From Changelog:

- CLOEXEC file descriptor leaks fixed on Linux >= 2.6.28 with glibc >= 2.10.

    Irreparable race condition leaks remain on other Unix platforms.
    This issue may have security implications on some deployments.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2011-02-07 16:00:15 UTC
Created attachment 261731 [details, diff]
stunnel-4.35-libwrap.patch
Comment 2 Stefan Behte (RETIRED) gentoo-dev Security 2011-02-07 16:37:32 UTC
Created attachment 261735 [details, diff]
stunnel-4.35-xforwarded-for.diff

Man pages changed
Comment 3 Stefan Behte (RETIRED) gentoo-dev Security 2011-02-07 16:40:34 UTC
Created attachment 261737 [details, diff]
stunnel-4.34-listen-queue.diff
Comment 4 Stefan Behte (RETIRED) gentoo-dev Security 2011-02-07 16:45:19 UTC
Created attachment 261739 [details]
stunnel-4.35.ebuild
Comment 5 Stefan Behte (RETIRED) gentoo-dev Security 2011-02-07 16:47:48 UTC
xforwarded-for was already stable (4.31-r1).

The listen-queue patch is new, (#344117) and was not in portage yet, so normally for security bumps, we would leave out the listen-queue patch.
Comment 6 Stefan Behte (RETIRED) gentoo-dev Security 2011-02-07 16:51:17 UTC
Created attachment 261741 [details]
stunnel-4.35.ebuild

new SRC_URI
Comment 7 Stefan Behte (RETIRED) gentoo-dev Security 2011-02-07 17:01:57 UTC
I've tested and can confirm that X-Forwarded-For works with 4.35.
Comment 8 Stefan Behte (RETIRED) gentoo-dev Security 2011-02-09 15:47:15 UTC
4.36 is out, it includes the listen-queue and libwrap patch.
I hope Mike will decide to include x-forwarded-for in 4.37.
Comment 9 Stefan Behte (RETIRED) gentoo-dev Security 2011-02-10 15:25:21 UTC
When asked for elaboration of the isse, Mike wrote:
------------------
Try this link:
http://kerneltrap.org/mailarchive/git-commits-head/2008/11/20/4175544
Comment 10 Stefan Behte (RETIRED) gentoo-dev Security 2011-02-10 20:59:53 UTC
4.36 is considered "in-development", but the changelog already listed it, thus my confusion. So let's got with 4.35 for now.
Comment 11 Lance Albertson (RETIRED) gentoo-dev 2011-03-02 06:17:20 UTC
Committed. Thanks for the patches and ebuild!
Comment 12 Lance Albertson (RETIRED) gentoo-dev 2011-03-02 06:18:09 UTC
Oops, I forgot this was a security bug. It still needs to be stabilized and tested. 
Comment 13 Stefan Behte (RETIRED) gentoo-dev Security 2011-03-30 08:47:53 UTC
Is this ready for stabilization?
Comment 14 Lance Albertson (RETIRED) gentoo-dev 2011-05-26 18:28:11 UTC
Pushed to the tree, thanks for the report!
Comment 15 Tim Sammut (RETIRED) gentoo-dev 2011-05-26 18:35:23 UTC
Hi, Lance, thanks for committing this. Please do not close security bugs. Is =net-misc/stunnel-4.35 suitable for stabilization?
Comment 16 Lance Albertson (RETIRED) gentoo-dev 2011-05-26 18:36:42 UTC
Oops, sorry about that. Yes it is.
Comment 17 Tim Sammut (RETIRED) gentoo-dev 2011-05-26 18:42:16 UTC
(In reply to comment #16)
> Oops, sorry about that. Yes it is.

Great, thanks, and no problemo.

Arches, please test and mark stable:
=net-misc/stunnel-4.35
Target keywords : "alpha amd64 arm hppa ppc ppc64 sparc x86"
Comment 18 Agostino Sarubbo gentoo-dev 2011-05-26 18:56:55 UTC
amd64 ok
Comment 19 Jeroen Roovers (RETIRED) gentoo-dev 2011-05-26 19:26:26 UTC
Stable for HPPA.
Comment 20 Kacper Kowalik (Xarthisius) (RETIRED) gentoo-dev 2011-05-26 22:04:15 UTC
*** Bug 349074 has been marked as a duplicate of this bug. ***
Comment 21 Kacper Kowalik (Xarthisius) (RETIRED) gentoo-dev 2011-05-27 06:15:02 UTC
ppc/ppc64 stable and x86/amd64 already done by ramereth
Comment 22 Raúl Porcel (RETIRED) gentoo-dev 2011-05-28 16:50:20 UTC
alpha/arm/ia64/sparc stable
Comment 23 Tim Sammut (RETIRED) gentoo-dev 2011-05-28 17:09:33 UTC
Thanks, everyone. GLSA Vote: no.
Comment 24 Pierre-Yves Rofes (RETIRED) gentoo-dev 2011-10-08 21:10:16 UTC
no too, closing