Bug 715605 - missing record in long_options array causes ipmidetectd segfaults
Summary: missing record in long_options array causes ipmidetectd segfaults
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: freeipmi
Version: 6.1
Hardware: All
OS: Linux
medium
medium
Target Milestone: rc
: ---
Assignee: Ales Ledvinka
QA Contact: Branislav Blaškovič
URL:
Whiteboard:
: 757710 (view as bug list)
Depends On: 460876 757710 1117295
Blocks: 840699
TreeView+ depends on / blocked
 
Reported: 2011-06-23 13:32 UTC by Petr Sklenar
Modified: 2016-09-20 04:32 UTC (History)
4 users (show)

Fixed In Version: freeipmi-1.2.1-1
Doc Type: Bug Fix
Doc Text:
Cause: Insufficient command line configuration valid parameter checks. Consequence: Crash while parsing the invalid command line arguments. Fix: Package rebased to version containing sufficient checks. Result: No undefined behaviour(crash) on invalid input.
Clone Of: 460876
Environment:
Last Closed: 2013-11-21 11:57:02 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2013:1640 0 normal SHIPPED_LIVE freeipmi bug fix and enhancement update 2013-11-20 21:53:36 UTC

Description Petr Sklenar 2011-06-23 13:32:18 UTC
this issue is on rhel6:
[root@test02-64 bz460876-ipmidetectd-segfaults]# /usr/sbin/ipmidetectd --unsupported
Segmentation fault (core dumped)
[root@test02-64 bz460876-ipmidetectd-segfaults]# echo $?
139
[root@test02-64 bz460876-ipmidetectd-segfaults]# rpm -qf /usr/sbin/ipmidetectd
freeipmi-ipmidetectd-0.7.16-3.el6.i686


+++ This bug was initially created as a clone of Bug #460876 +++

Description of problem:
The source file ipmidetectd_config.c does not contain {0, 0, 0, 0} as the last record in the long_options array, which is necessary for getopt_long(). This missing record causes that getopt_long() gets out of array bounds when searching for an unsupported long option.

Version-Release number of selected component (if applicable):
freeipmi-ipmidetectd-0.4.6-3.fc8

How reproducible:
Always

Steps to Reproduce:
$ /usr/sbin/ipmidetectd --debug
Segmentation fault
$ /usr/sbin/ipmidetectd --config-file
Segmentation fault
$ 
  
Actual results:
/usr/sbin/ipmidetectd is terminated (segmentation fault) if it is executed with unsupported long option

Expected results:
/usr/sbin/ipmidetectd is not terminated (segmentation fault) if it is executed with unsupported long option

Additional info:

--- Additional comment from triage.org on 2008-11-26 06:07:36 EST ---


This message is a reminder that Fedora 8 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 8.  It is Fedora's policy to close all
bug reports from releases that are no longer maintained.  At that time
this bug will be closed as WONTFIX if it remains open with a Fedora 
'version' of '8'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version' 
to a later Fedora version prior to Fedora 8's end of life.

Bug Reporter: Thank you for reporting this issue and we are sorry that 
we may not be able to fix it before Fedora 8 is end of life.  If you 
would still like to see this bug fixed and are able to reproduce it 
against a later version of Fedora please change the 'version' of this 
bug to the applicable version.  If you are unable to change the version, 
please add a comment here and someone will do it for you.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events.  Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

The process we are following is described here: 
http://fedoraproject.org/wiki/BugZappers/HouseKeeping

--- Additional comment from pknirsch on 2008-11-26 09:48:30 EST ---

Moving to rawhide.

--- Additional comment from triage.org on 2009-06-09 05:41:46 EDT ---


This bug appears to have been reported against 'rawhide' during the Fedora 11 development cycle.
Changing version to '11'.

More information and reason for this action is here:
http://fedoraproject.org/wiki/BugZappers/HouseKeeping

--- Additional comment from triage.org on 2010-04-27 08:13:15 EDT ---


This message is a reminder that Fedora 11 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 11.  It is Fedora's policy to close all
bug reports from releases that are no longer maintained.  At that time
this bug will be closed as WONTFIX if it remains open with a Fedora 
'version' of '11'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version' 
to a later Fedora version prior to Fedora 11's end of life.

Bug Reporter: Thank you for reporting this issue and we are sorry that 
we may not be able to fix it before Fedora 11 is end of life.  If you 
would still like to see this bug fixed and are able to reproduce it 
against a later version of Fedora please change the 'version' of this 
bug to the applicable version.  If you are unable to change the version, 
please add a comment here and someone will do it for you.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events.  Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

The process we are following is described here: 
http://fedoraproject.org/wiki/BugZappers/HouseKeeping

--- Additional comment from triage.org on 2010-06-28 06:43:38 EDT ---


Fedora 11 changed to end-of-life (EOL) status on 2010-06-25. Fedora 11 is 
no longer maintained, which means that it will not receive any further 
security or bug fix updates. As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of 
Fedora please feel free to reopen this bug against that version.

Thank you for reporting this bug and we are sorry it could not be fixed.

--- Additional comment from jsafrane on 2010-06-29 08:52:13 EDT ---

This one still segfaults in freeipmi-ipmidetectd-0.8.3-1.fc13, I'll look at it.

--- Additional comment from jsafrane on 2010-07-01 02:45:49 EDT ---

I've sent patch upstream and it was accepted: http://lists.gnu.org/archive/html/freeipmi-users/2010-06/msg00012.html (I hope the link is persistent).

I don't think it's necessary to patch Fedora package, the bug is harmless and freeipmi is released quite frequently.

Comment 2 RHEL Program Management 2011-07-06 01:12:33 UTC
This request was evaluated by Red Hat Product Management for
inclusion in the current release of Red Hat Enterprise Linux.
Because the affected component is not scheduled to be updated
in the current release, Red Hat is unfortunately unable to
address this request at this time. Red Hat invites you to
ask your support representative to propose this request, if
appropriate and relevant, in the next release of Red Hat
Enterprise Linux. If you would like it considered as an
exception in the current release, please ask your support
representative.

Comment 3 Ales Ledvinka 2013-05-17 08:19:24 UTC
*** Bug 757710 has been marked as a duplicate of this bug. ***

Comment 6 errata-xmlrpc 2013-11-21 11:57:02 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2013-1640.html


Note You need to log in before you can comment on or make changes to this bug.