| Summary: | Bad netgroup name causes ns-slapd to segfault | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 6 | Reporter: | Nalin Dahyabhai <nalin> |
| Component: | slapi-nis | Assignee: | Nalin Dahyabhai <nalin> |
| Status: | CLOSED ERRATA | QA Contact: | IDM QE LIST <seceng-idm-qe-list> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 6.2 | CC: | abokovoy, dpal, jgalipea, nalin, rcritten, rmeggins, spoore |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | slapi-nis-0.38-1.el6 | Doc Type: | Bug Fix |
| Doc Text: | Story Points: | --- | |
| Clone Of: | 796509 | Environment: | |
| Last Closed: | 2012-06-20 13:36:49 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Bug Depends On: | 796509 | ||
| Bug Blocks: | |||
|
Description
Nalin Dahyabhai
2012-03-06 20:04:27 UTC
Verified. Version :: ipa-server-2.2.0-4.el6.x86_64 Automated Test Results :: ipa-server-2.2.0-4.el6.x86_64 :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :: [ LOG ] :: netgroup_bz_800625: Bad netgroup name causes ns-slapd to segfault :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :: [ PASS ] :: Running 'ldapmodify -a -x -D "cn=Directory Manager" -w "Secret123" -f /tmp/netgroup_crash.ldif' :: [ PASS ] :: Running 'ipactl status > /netgroup_bz_800625.22323.out 2>&1' :: [ PASS ] :: BZ 800625 not found... :: [ LOG ] :: Duration: 5s :: [ LOG ] :: Assertions: 3 good, 0 bad :: [ PASS ] :: RESULT: netgroup_bz_800625: Bad netgroup name causes ns-slapd to segfault Manual Test Results :: [root@hp-xw6600-01 ipa-netgroup-cli]# ipa-compat-manage status Directory Manager password: Plugin Enabled [root@hp-xw6600-01 ipa-netgroup-cli]# cat << EOF > /tmp/netgroup_crash.ldif > dn: ipaUniqueID=170df1b8-688b-11e1-9cfb-5254000ea1b4,cn=ng,cn=alt,dc=testrelm,dc=com > objectClass: ipaobject > objectClass: ipaassociation > objectClass: ipanisnetgroup > cn: +badtestnetgroup > description: netgroup_with_plus_kills_dirsrv > nisDomainName: testrelm.com > ipaUniqueID: 170df1b8-688b-11e1-9cfb-5254000ea1b4 > EOF [root@hp-xw6600-01 ipa-netgroup-cli]# ldapmodify -a -x -D "cn=Directory Manager" -w "********" -f /tmp/netgroup_crash.ldif adding new entry "ipaUniqueID=170df1b8-688b-11e1-9cfb-5254000ea1b4,cn=ng,cn=alt,dc=testrelm,dc=com" [root@hp-xw6600-01 ipa-netgroup-cli]# ipactl status Directory Service: RUNNING KDC Service: RUNNING KPASSWD Service: RUNNING DNS Service: RUNNING MEMCACHE Service: RUNNING HTTP Service: RUNNING CA Service: RUNNING [root@hp-xw6600-01 ipa-netgroup-cli]# ldapsearch -x -D "cn=Directory Manager" -w "*********" -b "ipaUniqueID=170df1b8-688b-11e1-9cfb-5254000ea1b4,cn=ng,cn=alt,dc=testrelm,dc=com" # extended LDIF # # LDAPv3 # base <ipaUniqueID=170df1b8-688b-11e1-9cfb-5254000ea1b4,cn=ng,cn=alt,dc=testrelm,dc=com> with scope subtree # filter: (objectclass=*) # requesting: ALL # # 170df1b8-688b-11e1-9cfb-5254000ea1b4, ng, alt, testrelm.com dn: ipaUniqueID=170df1b8-688b-11e1-9cfb-5254000ea1b4,cn=ng,cn=alt,dc=testrelm, dc=com objectClass: ipaobject objectClass: ipaassociation objectClass: ipanisnetgroup cn: +badtestnetgroup description: netgroup_with_plus_kills_dirsrv nisDomainName: testrelm.com ipaUniqueID: 170df1b8-688b-11e1-9cfb-5254000ea1b4 # search result search: 2 result: 0 Success # numResponses: 2 # numEntries: 1 Also did a quick Manual Test for = in name: [root@hp-xw6600-01 ipa-netgroup-cli]# ldapmodify -a -x -D "$ROOTDN" -w "$ROOTDNPWD" dn: ipaUniqueID=170df1b8-688b-11e1-9cfb-5254000ea1a7,cn=ng,cn=alt,dc=testrelm,dc=com objectClass: ipaobject objectClass: ipaassociation objectClass: ipanisnetgroup cn: =badtestgroup description: netgroup_with_plus_kills_dirsrv nisDomainName: testrelm.com ipaUniqueID: 170df1b8-688b-11e1-9cfb-5254000ea1a7 adding new entry "ipaUniqueID=170df1b8-688b-11e1-9cfb-5254000ea1a7,cn=ng,cn=alt,dc=testrelm,dc=com" [root@hp-xw6600-01 ipa-netgroup-cli]# ldapsearch -x -D "$ROOTDN" -w "$ROOTDNPWD" -b ipaUniqueID=170df1b8-688b-11e1-9cfb-5254000ea1a7,cn=ng,cn=alt,dc=testrelm,dc=com # extended LDIF # # LDAPv3 # base <ipaUniqueID=170df1b8-688b-11e1-9cfb-5254000ea1a7,cn=ng,cn=alt,dc=testrelm,dc=com> with scope subtree # filter: (objectclass=*) # requesting: ALL # # 170df1b8-688b-11e1-9cfb-5254000ea1a7, ng, alt, testrelm.com dn: ipaUniqueID=170df1b8-688b-11e1-9cfb-5254000ea1a7,cn=ng,cn=alt,dc=testrelm, dc=com objectClass: ipaobject objectClass: ipaassociation objectClass: ipanisnetgroup cn: =badtestgroup description: netgroup_with_plus_kills_dirsrv nisDomainName: testrelm.com ipaUniqueID: 170df1b8-688b-11e1-9cfb-5254000ea1a7 # search result search: 2 result: 0 Success # numResponses: 2 # numEntries: 1 Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHBA-2012-0821.html |