Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 83685 - net-libs/openslp issues
Summary: net-libs/openslp issues
Status: RESOLVED DUPLICATE of bug 85347
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.novell.com/linux/security/...
Whiteboard: CONFIDENTIAL 200503??
Keywords:
Depends on:
Blocks:
 
Reported: 2005-03-01 07:16 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2008-11-05 08:50 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
openslp-1.1.5.AUD (openslp-1.1.5.AUD,7.62 KB, text/plain)
2005-03-01 07:19 UTC, Sune Kloppenborg Jeppesen (RETIRED)
no flags Details
openslp.audit.diff (openslp.audit.diff,18.23 KB, patch)
2005-03-01 07:19 UTC, Sune Kloppenborg Jeppesen (RETIRED)
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-03-01 07:16:46 UTC
From Vendor-Sec:

I've had a look at the openslp code (some service-location
protol implementation). Attached is the audit log and a patch
for these issues made by our maintainer. The strcat()
overflow in libslp/libslp_network.c is already fixed
in another diff as I was told so it is missing in the patch.
Issue is not public, if anyone of you also ships this
we should make a timeline.
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-03-01 07:19:00 UTC
Created attachment 52386 [details]
openslp-1.1.5.AUD
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-03-01 07:19:24 UTC
Created attachment 52387 [details, diff]
openslp.audit.diff
Comment 3 solar (RETIRED) gentoo-dev 2005-03-01 07:38:57 UTC
Package: net-libs/openslp
Maintainer: Error (Missing metadata.xml)

Existing keywords and pkg version.
openslp-1.0.11:  ppc s390 x86 ppc64 arm sparc alpha ia64 mips hppa amd64 

The following people have been involved with this package in the past.

2 kumba@gentoo.org
2 gmsoft@gentoo.org
1 woodchip@gentoo.org
1 verwilst@gentoo.org
1 tgall@gentoo.org
1 seemant@gentoo.org
1 randy@gentoo.org
1 raker@gentoo.org
1 manson@gentoo.org
1 liquidx@gentoo.org
1 gustavoz@gentoo.org
1 gbevin@gentoo.org
1 eradicator@gentoo.org
1 darkspecter@gentoo.org
1 cselkirk@gentoo.org
1 agriffis@gentoo.or
Comment 4 rob holland (RETIRED) gentoo-dev 2005-03-10 13:27:14 UTC
I've had a quick look at the diff and the source code. Specifical sldp_outgoing.c and sldp_incoming.c both trust the value in peek to allocate a buffer.

Pretty sure that can be abused for a heap overflow and be exploitable on systems without chunk-protection malloc patches.

If this needs a serious review please let me know, I've spent very little time on it.
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-03-14 10:41:59 UTC
Now public, but we should probably open a new bug for this if it applies to us.
Comment 6 Luke Macken (RETIRED) gentoo-dev 2005-03-15 07:20:36 UTC
Closing confidential bug.

*** This bug has been marked as a duplicate of 85347 ***