Bug 30185 - stunnel new security issue fixed upstream in 5.58
Summary: stunnel new security issue fixed upstream in 5.58
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-03-17 23:20 CET by David Walser
Modified: 2022-03-21 21:19 CET (History)
4 users (show)

See Also:
Source RPM: stunnel-5.57-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2022-03-17 23:20:18 CET
SUSE has issued an advisory on March 16:
https://lists.suse.com/pipermail/sle-security-updates/2022-March/010458.html
Comment 2 Lewis Smith 2022-03-18 08:31:39 CET
Different people maintain this, so having to assign it globally.

Assignee: bugsquad => pkg-bugs

Comment 3 Nicolas Salguero 2022-03-18 10:41:13 CET
Suggested advisory:
========================

The updated package fixes a security vulnerability.

References:
https://lists.suse.com/pipermail/sle-security-updates/2022-March/010458.html
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SF6GP7Y7QBDPSDEMYQPWKSOXKRHILQVP/
========================

Updated package in core/updates_testing:
========================
stunnel-5.63-1.mga8

from SRPM:
stunnel-5.63-1.mga8.src.rpm

Assignee: pkg-bugs => qa-bugs
Status: NEW => ASSIGNED
CC: (none) => nicolas.salguero

Thomas Backlund 2022-03-20 11:29:58 CET

Version: Cauldron => 8

Comment 4 Herman Viaene 2022-03-21 11:48:13 CET
MGA8-64 Plasma on Lenovo B50 in Dutch
No installation issues
Looking at previous updates ref to bug 12943 Comment 8. Trying to follow rather blindly.
Notice there are 2 executables now: stunnel and stunnel3
Did following changes to /etc/stunnel/stunnel.conf
Inserted line
fips = no
Uncommented the https section lin and uncommented and changed the 'accept' port it listens on to 4443 from 443.
The stunnel command gave an awfull lot of feedback, and  the ps and neststat command returned blank.
Tried
# stunnel3
[ ] Initializing inetd mode configuration
[ ] Clients allowed=500
[.] stunnel 5.63 on x86_64-mageia-linux-gnu platform
[.] Compiled with OpenSSL 1.1.1n  15 Mar 2022
[.] Running  with OpenSSL 1.1.1m  14 Dec 2021
[.] Threading:PTHREAD Sockets:POLL,IPv6 TLS:ENGINE,OCSP,PSK,SNI Auth:LIBWRAP
[ ] errno: (*__errno_location ())
[ ] Initializing inetd mode configuration
[.] Reading configuration from descriptor 3
[.] FIPS mode disabled
[ ] Compression enabled: 0 methods
[ ] No PRNG seeding was required
[!] Inetd mode: TLS server needs a certificate
[!] Configuration failed
[ ] Deallocating temporary section defaults

And that does not look good.

CC: (none) => herman.viaene

Comment 5 Dave Hodgins 2022-03-21 18:18:36 CET
The stunnel3 command also fails with "Configuration failed" for me, however
that is not a regressions.

It is working with /etc/stunnel/stunnel.conf having ...
[nntps]
client=yes
connect=news.eternal-september.org:563
cert=/etc/pki/tls/certs/stunnel.pem
accept=564
TIMEOUTconnect=60

I'm using leafnode to get nttps with ...
# grep -v -e ^'#' -e ^$ /etc/leafnode/config
expire = 20
server = localhost
port = 564
username = dwhodgins
password = munged
timeout = 300
timeout_fetchnews = 300
initialfetch = 500
nodesc = 1
maxage = 5
filterfile = /etc/leafnode/filters
debugmode = 0
create_all_links = 0
allow_8bit_headers = 1
article_despite_filter = 1
noxover = 1

Whiteboard: (none) => MGA8-64-OK
Keywords: (none) => validated_update
CC: (none) => davidwhodgins, sysadmin-bugs

Dave Hodgins 2022-03-21 19:29:08 CET

Keywords: (none) => advisory

Comment 6 Mageia Robot 2022-03-21 21:19:59 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0109.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.