Bug 29349 - fetchmail regression caused by CVE-2021-36386 fix
Summary: fetchmail regression caused by CVE-2021-36386 fix
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2021-08-10 15:49 CEST by David Walser
Modified: 2021-08-27 17:31 CEST (History)
1 user (show)

See Also:
Source RPM: fetchmail-6.4.8-4.1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2021-08-10 15:49:17 CEST
Upstream has announced version 6.4.21 on August 9:
https://www.openwall.com/lists/oss-security/2021/08/09/1

It fixes a regression from the fix we just did in Bug 29297:
https://www.fetchmail.info/fetchmail-SA-2021-01.txt

Mageia 8 is also affected.
David Walser 2021-08-10 15:49:27 CEST

Whiteboard: (none) => MGA8TOO

Comment 1 Thomas Backlund 2021-08-17 14:15:13 CEST
Cauldron fixed...

mga8 packages:


SRPM:
fetchmail-6.4.8-4.2.mga8.src.rpm

i586:
fetchmail-6.4.8-4.2.mga8.i586.rpm
fetchmailconf-6.4.8-4.2.mga8.i586.rpm
fetchmail-daemon-6.4.8-4.2.mga8.i586.rpm


x86_64:
fetchmail-6.4.8-4.2.mga8.x86_64.rpm
fetchmailconf-6.4.8-4.2.mga8.x86_64.rpm
fetchmail-daemon-6.4.8-4.2.mga8.x86_64.rpm

Whiteboard: MGA8TOO => (none)
Assignee: mageia => qa-bugs
Version: Cauldron => 8

Comment 2 Thomas Backlund 2021-08-17 17:52:32 CEST
advisory, added to svn:

type: bugfix
subject: Updated fetchmail packages fix logging regression
src:
  8:
   core:
     - fetchmail-6.4.8-4.2.mga8
description: |
  The recent fix for CVE-2021-36386 released in MGASA-2021-0391 introduced
  a regression causing truncation of messages logged to buffered outputs,
  predominantly --logfile. This also caused lines in the logfile to run
  into one another because the fragment containing the "\n" line-end
  character was usually lost.
references:
 - https://bugs.mageia.org/show_bug.cgi?id=29349
 - https://www.openwall.com/lists/oss-security/2021/08/09/1
 - https://www.fetchmail.info/fetchmail-SA-2021-01.txt

Keywords: (none) => advisory

Comment 3 Thomas Backlund 2021-08-26 13:44:28 CEST
Confirmation om discuss@ ml by Trish Fraser that the fix works.

Keywords: (none) => validated_update
Whiteboard: (none) => MGA8-64-OK
CC: (none) => sysadmin-bugs

Comment 4 Mageia Robot 2021-08-27 17:31:11 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGAA-2021-0175.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.