|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2004-1014: rpc.statd DoS | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Marcus Meissner <meissner> |
| Component: | Incidents | Assignee: | Ludwig Nussel <lnussel> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Major | ||
| Priority: | P3 - Medium | CC: | lnussel, postadal, ro, security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | CVE-2004-1014: CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P) | ||
| Found By: | --- | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Attachments: |
patch
patch ported to 1.0.1 nfs-utils.patch.maintained nfs-utils.patch.box |
||
|
Description
Ludwig Nussel
2004-12-07 21:51:54 UTC
Created attachment 26816 [details]
patch
no, the report was not missed. rpc.statd from nfs-utils was never packaged (at least not since SuSE 7.x) we use rpc.statd from the quota package. <!-- SBZ_reopen -->Reopened by okir@suse.de at Wed Dec 8 09:45:59 2004, took initial reporter lnussel@suse.de to cc Are you sure? There is only one rpc.statd. I think you're referring to rpc.rquotad, where indeed two versions exist (but the one from nfs-utils is essentially unmaintained) btw, rpc.rstatd does not come from nfs-utils on our distros, but from the rstatd RPM. The code there looks different. there is no change in SIGCHLD handling in rstatd, so I suspect we are affected too. -> reassign to maintainer statd != rstatd my bad not shipping -> close <!-- SBZ_reopen -->Reopened by meissner@suse.de at Wed Dec 8 10:48:56 2004 more coffee. its in older products and is in nfs-utils, so we are affecgted damn you're right... it's really in SLES8 ... patch for nfs-utils-1.0.1 (one hunk missing, n/a for version 1.0.1) Created attachment 26856 [details]
patch ported to 1.0.1
CAN-2004-1014 ok, done for 8.1,8.2,9.0 (added a few more %m replacements in rmtcall.c) 9.1 and newer do not have statd any more. are you going to create patchinfos ? yes. Please add the CAN number to the changelog if the package is not checked in yet Created attachment 26858 [details]
nfs-utils.patch.maintained
Created attachment 26859 [details]
nfs-utils.patch.box
packages approved CVE-2004-1014: CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P) |