Bug 29811 - e2guardian new security issue CVE-2021-44273
Summary: e2guardian new security issue CVE-2021-44273
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2021-12-24 14:17 CET by David Walser
Modified: 2021-12-30 17:43 CET (History)
6 users (show)

See Also:
Source RPM: e2guardian-5.3.4-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2021-12-24 14:17:11 CET
A security issue fixed upstream in e2guardian has been announced on December 23:
https://www.openwall.com/lists/oss-security/2021/12/23/2

Mageia 8 is also affected.
David Walser 2021-12-24 14:17:27 CET

Status comment: (none) => Patch available from upstream
Whiteboard: (none) => MGA8TOO

Comment 1 Nicolas Lécureuil 2021-12-26 19:37:51 CET
Fixed in mga8

src:
    - e2guardian-5.3.4-1.1.mga8

CC: (none) => mageia

Comment 2 Lewis Smith 2021-12-26 20:38:17 CET
Thank you NicolasL for fixing this in Cauldron so quickly. It would be odd not to assign the bug to you.
However, CC'ing DavidG (registered pkger) who might want to carry the update forward.

CC: mageia => geiger.david68210
Assignee: bugsquad => mageia

David Walser 2021-12-26 22:26:09 CET

Assignee: mageia => qa-bugs
CC: (none) => mageia
Status comment: Patch available from upstream => (none)
Whiteboard: MGA8TOO => (none)
Version: Cauldron => 8

Comment 3 Herman Viaene 2021-12-27 11:40:27 CET
MGA8-64 Plasma on Lenvo B50 in Dutch
No installation issues, installed also e2guardian-children-blacklists to get more preconfigured items.
Found some guidance from https://www.linux.com/training-tutorials/filter-content-your-home-network-e2guardian/
Looked in the config files and uncommented the line
.Include</etc/e2guardian/lists/blacklists/adult/domains>
in the file /etc/e2guardian/lists/bannedsitelist

It works with squid, so at CLI:
# systemctl  start squid   
[root@mach5 ~]# systemctl -l status squid
● squid.service - Squid Web Proxy Server
     Loaded: loaded (/usr/lib/systemd/system/squid.service; disabled; vendor preset: disabled)
     Active: active (running) since Mon 2021-12-27 10:52:43 CET; 3s ago
       Docs: man:squid(8)
    Process: 14320 ExecStartPre=/usr/sbin/squid --foreground -z -F (code=exited, status=0/SUCCESS)
   Main PID: 14324 (squid)
      Tasks: 4 (limit: 9397)
     Memory: 18.7M
        CPU: 108ms
     CGroup: /system.slice/squid.service
             ├─14324 /usr/sbin/squid --foreground -sYC
             ├─14326 (squid-1) --kid squid-1 --foreground -sYC
             ├─14327 (logfile-daemon) /var/log/squid/access.log
             └─14328 (pinger)

dec 27 10:52:43 mach5.hviaene.thuis squid[14326]: Using Least Load store dir selection
dec 27 10:52:43 mach5.hviaene.thuis squid[14326]: Set Current Directory to /var/spool/squid
dec 27 10:52:43 mach5.hviaene.thuis squid[14326]: Finished loading MIME types and icons.
dec 27 10:52:43 mach5.hviaene.thuis squid[14326]: HTCP Disabled.
dec 27 10:52:43 mach5.hviaene.thuis squid[14326]: Pinger socket opened on FD 14
dec 27 10:52:43 mach5.hviaene.thuis squid[14326]: Squid plugin modules loaded: 0
dec 27 10:52:43 mach5.hviaene.thuis squid[14326]: Adaptation support is off.
dec 27 10:52:43 mach5.hviaene.thuis squid[14326]: Accepting HTTP Socket connections at local=[::]:3128 remote=[::] FD 12 flags=9
dec 27 10:52:43 mach5.hviaene.thuis systemd[1]: Started Squid Web Proxy Server.
dec 27 10:52:44 mach5.hviaene.thuis squid[14326]: storeLateRelease: released 0 objects
changed the proxy setings in firefox
# systemctl  start e2guardian
[root@mach5 ~]# systemctl -l status e2guardian
● e2guardian.service - E2guardian Web Content Filter
     Loaded: loaded (/usr/lib/systemd/system/e2guardian.service; disabled; vendor preset: disabled)
     Active: active (running) since Mon 2021-12-27 10:53:42 CET; 3s ago
    Process: 14383 ExecStart=/usr/sbin/e2guardian (code=exited, status=0/SUCCESS)
   Main PID: 14384 (e2guardian)
      Tasks: 504 (limit: 9397)
     Memory: 32.3M
        CPU: 49ms
     CGroup: /system.slice/e2guardian.service
             └─14384 /usr/sbin/e2guardian

dec 27 10:53:42 mach5.hviaene.thuis systemd[1]: Starting E2guardian Web Content Filter...
dec 27 10:53:42 mach5.hviaene.thuis systemd[1]: e2guardian.service: Failed to parse PID from file /run/e2guardian.pid: Invalid argument
dec 27 10:53:42 mach5.hviaene.thuis e2guardian[14384]: Started successfully.
dec 27 10:53:42 mach5.hviaene.thuis systemd[1]: Started E2guardian Web Content Filter.
Pointed firefox to some nasty site and got blocked, so i works OK.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => herman.viaene

Comment 4 Thomas Andrews 2021-12-28 00:00:59 CET
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Dave Hodgins 2021-12-30 03:58:30 CET

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 5 Mageia Robot 2021-12-30 17:43:07 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0594.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.