Bug 149253 - cfengine rsa heap remote exploit
Summary: cfengine rsa heap remote exploit
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: cfengine
Version: 3
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Jeff Sheltren
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2005-02-21 17:50 UTC by Ville Skyttä
Modified: 2007-11-30 22:11 UTC (History)
0 users

Fixed In Version: 2.1.8
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2005-03-25 16:22:27 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Ville Skyttä 2005-02-21 17:50:46 UTC
Dunno if this is present in the cfengine package currently in extras, but
probably worth checking out:

http://www.securityfocus.com/archive/1/390947/2005-02-18/2005-02-24/1

(I'm not a cfengine user, just happened to notice this message on Bugtraq.)

Comment 1 Juha Ylitalo 2005-02-21 18:43:54 UTC
At least the code in given URL would seem to indicate that its targeted against
2.1.7p1 and FC3 extras has 2.1.9p2. Also here is what Mark Burgess (author of
cfengine) has written in their mailing list
(http://lists.gnu.org/archive/html/help-cfengine/2005-02/msg00115.html)
[begin quote]
This is not enough information to go on. Where does this come from and
when did it appear? It appears to be old. (2.1.7). In that case it
refers to a bug that was patched in 2.1.8.  More information please.
[end quote]

Comment 2 Michael Schwendt 2005-02-23 17:46:44 UTC
So are you still maintaining cfengine?

Comment 3 Juha Ylitalo 2005-02-23 19:57:57 UTC
I am not currently using cfengine anywhere in real life and don't seem to have
lot of freetime, so if someone has interest to take it as his/her responsible, I
don't have any objections against it.
Reason, why I checked this case was mostly for professional curiosity and I know
couple people, who are using cfengine on their environments.

Comment 4 Jeff Sheltren 2005-03-25 16:22:27 UTC
Fixed in 2.1.8.

Currently extras is providing 2.1.13, so this shouldn't be an issue.


Note You need to log in before you can comment on or make changes to this bug.