Bug 29220 - nginx, sendmail, vsftpd new security issue CVE-2021-3618
Summary: nginx, sendmail, vsftpd new security issue CVE-2021-3618
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2021-07-04 21:13 CEST by David Walser
Modified: 2021-12-08 21:05 CET (History)
7 users (show)

See Also:
Source RPM: nginx-1.20.1-1.mga9.src.rpm, sendmail-8.16.1-1.mga8.src.rpm, vsftpd-3.0.3-11.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2021-07-04 21:13:14 CEST
Fedora has issued an advisory today (July 4):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/44SPREQ2R4IE2VUUO2HVCFTUGDCYSXAD/

The issue is fixed upstream in vsftpd 3.0.4, nginx 1.21.0, and sendmail 8.17.

Mageia 8 is also affected.
David Walser 2021-07-04 21:13:44 CEST

Status comment: (none) => Fixed upstream in vsftpd 3.0.4, nginx 1.21.0, sendmail 8.17
Whiteboard: (none) => MGA8TOO

Comment 1 Lewis Smith 2021-07-05 20:53:11 CEST
Given the 3 SRPMS involved (of which one has no obvious maintainer), assigning this globally; CC'ing Stig for nginx, cjw for sendmail.

CC: (none) => cjw, smelror
Assignee: bugsquad => pkg-bugs

Comment 2 Stig-Ørjan Smelror 2021-07-05 23:18:18 CEST
Regarding nginx, it's probably fixed in 1.20.1 as well. 1.21.0 is their development version that I don't want to push to mga8.
Comment 3 Stig-Ørjan Smelror 2021-07-05 23:21:48 CEST
Yes.

"nginx-1.20.1 stable and nginx-1.21.0 mainline versions have been released, with a fix for the 1-byte memory overwrite vulnerability in resolver (CVE-2021-23017)."
https://nginx.org/
Comment 4 Stig-Ørjan Smelror 2021-07-05 23:25:32 CEST
Cauldron has already been updated to 1.20.1. Looks like it's been updated with an upstream patch for mga8 by David Walser on 2021-06-28.

------------------------------------------------------------------------
r1734115 | luigiwalser | 2021-06-28 18:38:21 +0200 (Mon, 28 Jun 2021) | 1 line

add upstream patch to fix CVE-2021-23017

Whiteboard: MGA8TOO => (none)
Version: Cauldron => 8

Comment 5 David Walser 2021-07-05 23:49:58 CEST
You got the wrong CVE (and there's two other packages to fix).

See the RedHat bug for a link to the nginx commit that fixed this issue.

Whiteboard: (none) => MGA8TOO
Version: 8 => Cauldron

Comment 6 David Walser 2021-10-22 00:04:46 CEST
Fedora has issued an advisory for vsftpd today (October 21):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/TKXMYKALTHIBJLDHQPBKNQK2FWVOSIG7/
Comment 7 Nicolas Lécureuil 2021-12-01 00:25:02 CET
fixed in cauldron

Whiteboard: MGA8TOO => (none)
Version: Cauldron => 8
CC: (none) => mageia

Comment 8 Nicolas Lécureuil 2021-12-01 00:26:47 CET
From: https://security-tracker.debian.org/tracker/CVE-2021-3618
this is fixed in sendmail 8.16.1 ( so mga8 is not affected ).


src:
    - nginx-1.18.0-5.2.mga8
    - vsftpd-3.0.5-1.mga8

Status comment: Fixed upstream in vsftpd 3.0.4, nginx 1.21.0, sendmail 8.17 => (none)
Assignee: pkg-bugs => qa-bugs

Comment 9 Brian Rockwell 2021-12-04 03:09:29 CET
MGa8-64, gnome

To satisfy dependencies, the following package(s) also need to be installed:

- lib64pcre16_0-8.44-1.mga8.x86_64
- lib64pcre32_0-8.44-1.mga8.x86_64
- lib64pcreposix1-8.44-1.mga8.x86_64
- pcre-8.44-1.mga8.x86_64
- webserver-base-2.0-15.mga8.noarch
- and of course nginx

-- rebooted

went into services and started nginx

Welcome to nginx 1.18.0 on Mageia!

CC: (none) => brtians1

Comment 10 Brian Rockwell 2021-12-04 03:32:14 CET
MG8-64, Gnome
installed vsftpd

started it in services
realized I needed to configure it
edited the vsftpd.conf file 
restarted service

test ftp

worked
Comment 11 Brian Rockwell 2021-12-04 03:33:28 CET
sendmail - do I need to test this?
Comment 12 David Walser 2021-12-04 04:32:30 CET
No, Sendmail apparently didn't need to be updated.

Whiteboard: (none) => MGA8-64-OK

Comment 13 Thomas Andrews 2021-12-05 18:19:17 CET
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Dave Hodgins 2021-12-08 01:21:08 CET

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 14 Mageia Robot 2021-12-08 21:05:24 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0540.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.