Compare commits

...
Sign in to create a new pull request.

8 commits

Author SHA1 Message Date
Jan Synacek
45e8dedc63 Fix tcpmux security
Resolves: #820318 (CVE-2012-0862)
2012-05-17 09:11:31 +02:00
Vojtech Vitek (V-Teq)
fffbdd6c66 Release build 2:2.3.14-36 2011-04-21 15:35:37 +02:00
Vojtech Vitek (V-Teq)
3a87b00842 - Fix build warning about "dereferencing type-punned pointer"
- Avoid possible hang while logging an unexpected signal
- Let RPC services bind to a specific port
2011-04-21 15:34:58 +02:00
Vojtech Vitek (V-Teq)
743e7109a4 Release build 2:2.3.14-35 2011-02-18 15:14:36 +01:00
Vojtech Vitek (V-Teq)
8cad70d099 - fix crash when application's logfile hit size limit
Related: #244063
2011-02-18 15:12:00 +01:00
Vojtech Vitek (V-Teq)
4619c0cb18 Add note about -pie -PIE patches to %build configure section 2011-02-18 15:12:00 +01:00
Vojtech Vitek (V-Teq)
a7049f7689 Release build 2:2.3.14-34 2011-02-15 17:01:40 +01:00
Vojtech Vitek (V-Teq)
333089beed - Add -Wl,-z,relro,-z,now to LDFLAGS 2011-02-15 17:01:18 +01:00
6 changed files with 178 additions and 1 deletions

View file

@ -0,0 +1,17 @@
244063: RHEL4 SIGSEGV in xinetd when application's logfile hit size limit
Written-By: Jan Safranek <jsafrane@redhat.com>
Initialize xl_callback_arg, so xinetd does not crash when it gets dereferenced.
diff -up xinetd-2.3.13/libs/src/xlog/xlog.c.orig xinetd-2.3.13/libs/src/xlog/xlog.c
--- xinetd-2.3.13/libs/src/xlog/xlog.c.orig 2003-05-31 23:58:58.000000000 +0200
+++ xinetd-2.3.13/libs/src/xlog/xlog.c 2007-12-05 15:31:08.000000000 +0100
@@ -216,6 +216,7 @@ int xlog_control( xlog_h pxlog, xlog_cmd
case XLOG_CALLBACK:
xp->xl_callback = va_arg( ap, voidfunc ) ;
+ xp->xl_callback_arg = va_arg( ap, void * );
break ;
case XLOG_GETFLAG:

View file

@ -0,0 +1,22 @@
diff --git a/sensor.c b/sensor.c
index 09d0877..e65018c 100644
--- a/xinetd/sensor.c
+++ b/xinetd/sensor.c
@@ -100,14 +100,15 @@ void process_sensor( const struct service *sp, const union xsockaddr *addr)
{
/* Here again, eh?...update time stamp. */
char *exp_time;
- time_t stored_time;
+ int stored_time;
item_matched--; /* Is # plus 1, to even get here must be >= 1 */
exp_time = pset_pointer( global_no_access_time, item_matched ) ;
if (exp_time == NULL)
return ;
- if ( parse_base10(exp_time, (int *)&stored_time) )
+ /* FIXME: Parse (long int) instead of (int) prior to possible Y2K38 bug. */
+ if ( parse_base10(exp_time, &stored_time ) )
{ /* if never let them off, bypass */
if (stored_time != -1)
{

View file

@ -0,0 +1,30 @@
commit 1b91f7b0f67fba11ea8bbcdddef844656434c53c
Author: Jeffrey Bastian <jbastian@redhat.com>
Date: Tue Aug 17 13:45:20 2010 -0500
Let RPC services bind to a port
diff --git a/xinetd/service.c b/xinetd/service.c
index 9f21f93..5d26885 100644
--- a/xinetd/service.c
+++ b/xinetd/service.c
@@ -165,6 +165,7 @@ static status_e activate_rpc( struct service *sp )
socklen_t sin_len = sizeof(tsin);
unsigned long vers ;
struct service_config *scp = SVC_CONF( sp ) ;
+ uint16_t service_port = SC_PORT( scp ) ;
struct rpc_data *rdp = SC_RPCDATA( scp ) ;
char *sid = SC_ID( scp ) ;
unsigned registered_versions = 0 ;
@@ -181,9 +182,11 @@ static status_e activate_rpc( struct service *sp )
}
if( SC_IPV4( scp ) ) {
tsin.sa_in.sin_family = AF_INET ;
+ tsin.sa_in.sin_port = htons( service_port ) ;
sin_len = sizeof(struct sockaddr_in);
} else if( SC_IPV6( scp ) ) {
tsin.sa_in6.sin6_family = AF_INET6 ;
+ tsin.sa_in6.sin6_port = htons( service_port );
sin_len = sizeof(struct sockaddr_in6);
}

View file

@ -0,0 +1,27 @@
--- a/xinetd/signals.c 2009-05-07 05:56:52.000000000 -0400
+++ b/xinetd/signals.c.new 2009-05-07 05:56:44.000000000 -0400
@@ -389,9 +390,11 @@
break ;
default:
- msg( LOG_NOTICE, func, "Unexpected signal %s", sig_name( sig ) ) ;
- if ( debug.on && sig == SIGINT )
- exit( 1 ) ;
+ /* Let my_handler() queue this signal for later logging.
+ Calling msg() and thus syslog() directly here can hang up
+ the process, trying to acquire an already acquired lock,
+ because another syslog() could have been the interrupted code. */
+ my_handler(sig);
}
}
@@ -495,6 +497,9 @@
default:
msg(LOG_ERR, func, "unexpected signal: %s in signal pipe",
sig_name(sig));
+
+ if ( debug.on && sig == SIGINT )
+ exit( 1 ) ;
}
}
}

View file

@ -0,0 +1,49 @@
--- xinetd-2.3.14/xinetd/builtins.c.old 2012-02-15 16:29:48.263844700 -0600
+++ xinetd-2.3.14/xinetd/builtins.c 2012-02-15 16:37:52.209594438 -0600
@@ -560,17 +560,16 @@
/* Found the pointer. Validate its type.
*/
scp = SVC_CONF( sp );
-/*
- if ( ! SVC_IS_MUXCLIENT( sp ) )
+
+ if ( ! SVC_IS_MUXCLIENT( sp ) && ! SVC_IS_MUXPLUSCLIENT( sp ) )
{
if ( debug.on )
{
msg(LOG_DEBUG, "tcpmux_handler", "Non-tcpmux service name: %s.",
svc_name);
}
- exit(0);
+ continue;
}
-*/
/* Send the accept string if we're a PLUS (+) client.
*/
@@ -597,6 +596,19 @@
msg(LOG_DEBUG, "tcpmux_handler", "Service name %s not found.",
svc_name);
}
+
+ /* If a service was not found, we should say so. */
+ if ( Swrite( descriptor, TCPMUX_NOT_FOUND, sizeof( TCPMUX_NOT_FOUND ) ) !=
+ sizeof ( TCPMUX_NOT_FOUND ) )
+ {
+ msg(LOG_ERR, "tcpmux_handler", "Not found write failed for %s.",
+ svc_name);
+ exit(0);
+ }
+
+ /* Flush and exit, nothing to do */
+ Sflush( descriptor );
+ Sclose( descriptor );
exit(0);
}
--- xinetd-2.3.14/xinetd/service.h.old 2012-02-15 16:29:34.186942629 -0600
+++ xinetd-2.3.14/xinetd/service.h 2012-02-15 16:30:19.009446694 -0600
@@ -114,2 +114,3 @@
#define TCPMUX_ACK "+Go\r\n"
+#define TCPMUX_NOT_FOUND "-Service name not found\r\n"
/*

View file

@ -1,7 +1,7 @@
Summary: A secure replacement for inetd
Name: xinetd
Version: 2.3.14
Release: 33%{?dist}
Release: 37%{?dist}
License: xinetd
Group: System Environment/Daemons
Epoch: 2
@ -39,6 +39,12 @@ Patch15: xinetd-2.3.14-ipv6confusion.patch
# This fixes bug #593904 - online reconfiguration caused log message
# flood when turning off UDP service
Patch16: xinetd-2.3.14-udp-reconfig.patch
Patch17: xinetd-2.3.13-log-crash.patch
Patch18: xinetd-2.3.14-rpc-specific-port.patch
Patch19: xinetd-2.3.14-signal-log-hang.patch
Patch20: xinetd-2.3.14-fix-type-punned-ptr.patch
# CVE-2012-0862
Patch21: xinetd-2.3.14-tcpmux-nonmux-security.patch
BuildRequires: autoconf, automake
BuildRequires: libselinux-devel >= 1.30
@ -83,11 +89,18 @@ located in the /etc/xinetd.d directory.
%patch14 -p1 -b .clean-pfd
%patch15 -p1 -b .ipv6confusion
%patch16 -p1 -b .udp-reconfig
%patch17 -p1 -b .log-crash
%patch18 -p1 -b .rpc-specific-port
%patch19 -p1 -b .signal-log-hang
%patch20 -p1 -b .fix-type-punned-ptr
%patch21 -p1 -b .tcpmux-security
aclocal
autoconf
%build
# -pie -PIE flags added by separate patches
export LDFLAGS="$LDFLAGS -Wl,-z,relro,-z,now"
%configure --with-loadavg --with-inet6 %{!?tcp_wrappers:--with-libwrap} --with-labeled-networking
make
@ -142,6 +155,25 @@ fi
%{_mandir}/*/*
%changelog
* Thu May 17 2012 Jan Synáček <jsynacek@redhat.com> - 2:2.3.14-37
- Fix tcpmux security
- Resolves: #820318 (CVE-2012-0862)
* Thu Apr 21 2011 Vojtech Vitek (V-Teq) <vvitek@redhat.com> - 2:2.3.14-36
- Fix build warning about "dereferencing type-punned pointer"
Related: #695674
- Avoid possible hang while logging an unexpected signal
Related: #501604
- Let RPC services bind to a specific port
Related: #624800
* Fri Feb 18 2011 Vojtech Vitek (V-Teq) <vvitek@redhat.com> - 2:2.3.14-35
- fix crash when application's logfile hit size limit
Related: #244063
* Mon Feb 14 2011 Vojtech Vitek (V-Teq) <vvitek@redhat.com> - 2:2.3.14-34
- Add -Wl,-z,relro,-z,now to LDFLAGS
* Mon Feb 07 2011 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2:2.3.14-33
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild