Bug 18135 - vtun new DoS security issue
Summary: vtun new DoS security issue
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/682570/
Whiteboard: advisory mga5-64-ok
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2016-04-05 19:44 CEST by David Walser
Modified: 2016-04-27 11:14 CEST (History)
2 users (show)

See Also:
Source RPM: vtun-3.0.2-10.mga5.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2016-04-05 19:44:58 CEST
Fedora has issued an advisory today (April 5):
https://lists.fedoraproject.org/pipermail/package-announce/2016-April/181383.html

Updated and patched packages uploaded for Mageia 5 and Cauldron.

Advisory:
========================

Updated vtun package fixes security vulnerability:

A vulnerability was found in the vtun package. When you send a SIGHUP to a vtun
client process and it cannot connect to the remote server, vtun tries to
reconnect without sleep between each attempt. In result, the vtun process uses
a lot of CPU, and writes to syslog without limit.

The vtun package has been updated to version 3.0.3 and patched to fix this
issue and other bugs.

References:
http://vtun.sourceforge.net/ChangeLog
https://lists.fedoraproject.org/pipermail/package-announce/2016-April/181383.html
========================

Updated packages in core/updates_testing:
========================
vtun-3.0.3-1.mga5

from vtun-3.0.3-1.mga5.src.rpm
Comment 1 William Kenney 2016-04-07 19:07:16 CEST
In VirtualBox, M5, KDE, 64-bit

Package(s) under test:
vtun

default install of vtun

[root@localhost wilcal]# urpmi vtun
Package vtun-3.0.2-10.mga5.x86_64 is already installed

Is there a simple way we can use vtun to set up an IP tunnel between
two Mageia systems on a LAN. Without it becoming a career thing?

CC: (none) => wilcal.int

Comment 2 claire robinson 2016-04-23 13:13:25 CEST
Just ensuring it updates cleanly, which it does. Shows post failure when restarting the vtund/vtunc services but the package doesn't provide services by default.

Whiteboard: (none) => mga5-64-ok

Comment 3 claire robinson 2016-04-23 14:47:06 CEST
Validating. Advisory uploaded.

Keywords: (none) => validated_update
Whiteboard: mga5-64-ok => advisory mga5-64-ok
CC: (none) => sysadmin-bugs

Comment 4 Mageia Robot 2016-04-25 09:58:00 CEST
An update for this issue has been pushed to the Mageia Updates repository.

http://advisories.mageia.org/MGASA-2016-0146.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED

Comment 5 David Walser 2016-04-27 11:14:21 CEST
CVE request:
http://openwall.com/lists/oss-security/2016/04/26/1

Note You need to log in before you can comment on or make changes to this bug.