Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

opensmtpd: 6.6.3p1 -> 6.6.4p1 #80978

Merged
merged 1 commit into from Feb 24, 2020
Merged

opensmtpd: 6.6.3p1 -> 6.6.4p1 #80978

merged 1 commit into from Feb 24, 2020

Conversation

andir
Copy link
Member

@andir andir commented Feb 24, 2020

Motivation for this change

Release notes aren't available at this time [1] it is likely to be
related to a recent mail to oss-security (either [2] or [3]).

[1] https://www.mail-archive.com/misc@opensmtpd.org/msg04888.html
[2] https://www.openwall.com/lists/oss-security/2020/02/24/5
[3] https://www.openwall.com/lists/oss-security/2020/02/24/4

Things done
  • Tested using sandboxing (nix.useSandbox on NixOS, or option sandbox in nix.conf on non-NixOS linux)
  • Built on platform(s)
    • NixOS
    • macOS
    • other Linux distributions
  • Tested via one or more NixOS test(s) if existing and applicable for the change (look inside nixos/tests)
  • Tested compilation of all pkgs that depend on this change using nix-shell -p nixpkgs-review --run "nixpkgs-review wip"
  • Tested execution of all binary files (usually in ./result/bin/)
  • Determined the impact on package closure size (by running nix path-info -S before and after)
  • Ensured that relevant documentation is up to date
  • Fits CONTRIBUTING.md.

Release notes aren't available at this time [1] it is likely to be
related to a recent mail to oss-security (either [2] or [3]).

[1] https://www.mail-archive.com/misc@opensmtpd.org/msg04888.html
[2] https://www.openwall.com/lists/oss-security/2020/02/24/5
[3] https://www.openwall.com/lists/oss-security/2020/02/24/4
Copy link
Member

@lsix lsix left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nix-review is happy, and nixos/tests/opensmtpd.nix is successful.

All green lights for me!

Thanks for such quick reaction time.

@Ekleog
Copy link
Member

Ekleog commented Feb 24, 2020

Looks like my internet connection got beaten by your ability to run nixos/tests/opensmtpd.nix locally faster; so let's merge :)

@Ekleog Ekleog merged commit 692571b into NixOS:master Feb 24, 2020
@andir
Copy link
Member Author

andir commented Feb 24, 2020

We still have to backport some version of those fixes to 19.09 and 20.03. As at least one of them provides some kind of remote code execution this has rather high severity.

Thoughts? @Ekleog

@Ekleog
Copy link
Member

Ekleog commented Feb 24, 2020 via email

@andir andir mentioned this pull request Feb 24, 2020
10 tasks
@andir
Copy link
Member Author

andir commented Feb 24, 2020 via email

@Ekleog
Copy link
Member

Ekleog commented Feb 24, 2020

Continuing discussion on #80993

As for 19.09, I've looked quickly, and OpenSMTPD/OpenSMTPD@b8a9e92 looks like the most likely culprit to me, though all commits from today will probably be needed to get something that actually works, given how they look from a cursory glance.

Unfortunately, I won't be able to look more into it before two or three days have elapsed, but I would guess that backporting this series of commits would probably work, though I clearly haven't looked enough into it to be confident that it would actually solve the issue -- my question on opensmtpd's IRC is also yet without answer, and I'll try to report the answer here should one arise before 2-3 days, though I'm not sure I'll have access to a computer before then.

@Ekleog
Copy link
Member

Ekleog commented Feb 24, 2020

Correction: the diff that would need backporting is OpenSMTPD/OpenSMTPD@6.6.3p1...6.6.4p1 ; don't know why I wasn't able to find the 6.6.4p1 tag before

@obadz
Copy link
Contributor

obadz commented Mar 16, 2020

Looks to me like backport to 19.09 never happened leaving servers exposed to RCE ?!? :-(

obadz added a commit to obadz/nixpkgs that referenced this pull request Mar 17, 2020
obadz pushed a commit that referenced this pull request Mar 17, 2020
This reverts commit 4f69f2c.

We backported the latest opensmtpd version.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants