| Summary: | TFTP Client x64: Buffer overflow on file putting | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Luzemário Dantas <luzemario> |
| Component: | RPM Packages | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | normal | ||
| Priority: | Normal | CC: | davidwhodgins, lists.jjorge, sysadmin-bugs, tmb |
| Version: | 1 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Source RPM: | tftp-5.0-6.mga1.x86_64 | CVE: | |
| Status comment: | |||
|
Description
Luzemário Dantas
2011-06-16 03:07:57 CEST
José Jorge
2011-10-17 14:04:46 CEST
CC:
(none) =>
lists.jjorge Fedora has a patch to fix that, I am applying it.
José Jorge
2011-10-17 14:09:44 CEST
Status:
NEW =>
ASSIGNED 5.1 version in Cauldron fixes that. 5.0 version in Mageia 1 has the same problem, so I only applied the patch. Qa Team, please test with this command : tftp -m binary localhost -c put one_file It should not crash anymore with tftp-5.0-7.1.
José Jorge
2011-10-17 17:56:47 CEST
Assignee:
lists.jjorge =>
qa-bugs Testing complete on i586 for the srpm tftp-5.0-7.1.mga1.src.rpm I confirmed that the core release version crashed with a buffer overflow. I also installed tftp-server, and added "-c -p" to the options in /etc/xinetd.d/tftp. (restart the service xinetd after changing), I also changed the owner of the /var/lib/tftpboot directory to nobody, so that the server could write to it. Note that the tftp-server will normally only be used to provide files, in it's default configuration, so these are not config problems for the server. Before the server was set up, the tftp command would timeout. With it installed/setup, the upload works. CC:
(none) =>
davidwhodgins Tested OK x86_64 using Dave's procedure. Update validated Advisory ----------------- This update to tftp corrects a crash due to a buffer overflow when putting a binary file onto a server. Mageia Bug: https://bugs.mageia.org/show_bug.cgi?id=1816 ----------------- SRPM: tftp-5.0-7.1.mga1.src.rpm Could sysadmin please push from core/updates testing to core/updates Thankyou! Keywords:
(none) =>
validated_update
claire robinson
2011-10-18 16:34:30 CEST
Hardware:
x86_64 =>
All
claire robinson
2011-10-18 16:34:40 CEST
Version:
Cauldron =>
1 Update pushed. Status:
ASSIGNED =>
RESOLVED |