Bug 136070 - [security] please update net-mgmt/nfsen to 1.3.2
Summary: [security] please update net-mgmt/nfsen to 1.3.2
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: Wesley Shields
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2009-06-26 16:20 UTC by Bjoern Engels
Modified: 2009-07-10 00:29 UTC (History)
1 user (show)

See Also:


Attachments
nfsen.patch (510 bytes, patch)
2009-06-26 16:47 UTC, Bjoern Engels
no flags Details | Diff
nfsen-1.3.2.patch (10.11 KB, patch)
2009-07-07 23:35 UTC, Mohacsi Janos
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Bjoern Engels 2009-06-26 16:20:01 UTC
Quoting http://sourceforge.net/forum/forum.php?forum_id=967583
  Due to double input checking, a remote command execution security bug
  exists in all NfSen versions 1.3 and 1.3.1. Users are requested to
  update to nfsen-1.3.2.

Fix: 

Upgrade to nfsen-1.3.2
Comment 1 Edwin Groothuis freebsd_committer freebsd_triage 2009-06-26 16:20:10 UTC
Maintainer of net-mgmt/nfsen,

Please note that PR ports/136070 has just been submitted.

If it contains a patch for an upgrade, an enhancement or a bug fix
you agree on, reply to this email stating that you approve the patch
and a committer will take care of it.

The full text of the PR can be found at:
    http://www.freebsd.org/cgi/query-pr.cgi?pr=ports/136070

-- 
Edwin Groothuis via the GNATS Auto Assign Tool
edwin@FreeBSD.org
Comment 2 Edwin Groothuis freebsd_committer freebsd_triage 2009-06-26 16:20:12 UTC
State Changed
From-To: open->feedback

Awaiting maintainers feedback (via the GNATS Auto Assign Tool)
Comment 3 Bjoern Engels 2009-06-26 16:47:23 UTC
Hi,

please find attached patch file to mark ports/net-mgmt/nfsen as
FORBIDDEN.

Kind regards
Bjoern
-- 
Bjoern Engels                                                OpenIT GmbH
engels@openit.de                                    In der Steele 33a-41
PGP keyID 1024D/895F13C3                             D-40599 Duesseldorf
________________________________________________________________________
HRB 38815 Amtsgericht Duesseldorf                    USt-Id DE 812951861
         Geschaeftsfuehrer: Oliver Haakert, Maurice Kemmann
Comment 4 Wesley Shields freebsd_committer freebsd_triage 2009-07-02 19:47:54 UTC
Responsible Changed
From-To: freebsd-ports-bugs->wxs

I'll take it.
Comment 5 dfilter service freebsd_committer freebsd_triage 2009-07-03 02:35:27 UTC
wxs         2009-07-03 01:35:18 UTC

  FreeBSD ports repository

  Modified files:
    security/vuxml       vuln.xml 
  Log:
  - Document remote command execution in net-mgmt/nfsen
  
  PR:             ports/136070
  Submitted by:   Bjoern Engels <engels@openit.de>
  
  Revision  Changes    Path
  1.1978    +28 -1     ports/security/vuxml/vuln.xml
_______________________________________________
cvs-all@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/cvs-all
To unsubscribe, send any mail to "cvs-all-unsubscribe@freebsd.org"
Comment 6 dfilter service freebsd_committer freebsd_triage 2009-07-03 02:36:18 UTC
wxs         2009-07-03 01:36:09 UTC

  FreeBSD ports repository

  Modified files:
    net-mgmt/nfsen       Makefile 
  Log:
  - Mark FORBIDDEN due to security vulnerability.
  
  PR:             ports/136070
  Submitted by:   Bjoern Engels <engels@openit.de>
  Security:       70372cda-6771-11de-883a-00e0815b8da8
  
  Revision  Changes    Path
  1.13      +2 -0      ports/net-mgmt/nfsen/Makefile
_______________________________________________
cvs-all@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/cvs-all
To unsubscribe, send any mail to "cvs-all-unsubscribe@freebsd.org"
Comment 7 Wesley Shields freebsd_committer freebsd_triage 2009-07-03 02:36:50 UTC
State Changed
From-To: feedback->analyzed

I've marked the port as forbidden but will be leaving this PR in analyzed state in the hopes that the maintainer will produce a patch to update to 1.3.2 (the fixed version).
Comment 8 Mohacsi Janos 2009-07-07 23:35:40 UTC
Dear FreeBSD commiters,
 	Here I send the patch for upgrade net-mgmt/nfsen to 1.3.2.

Janos Mohacsi
Network Engineer, Research Associate, Head of Network Planning and Projects
NIIF/HUNGARNET, HUNGARY
Key 70EF9882: DEC2 C685 1ED4 C95A 145F  4300 6F64 7B00 70EF 9882

On Fri, 26 Jun 2009, Edwin Groothuis wrote:

> Maintainer of net-mgmt/nfsen,
>
> Please note that PR ports/136070 has just been submitted.
>
> If it contains a patch for an upgrade, an enhancement or a bug fix
> you agree on, reply to this email stating that you approve the patch
> and a committer will take care of it.
>
> The full text of the PR can be found at:
>    http://www.freebsd.org/cgi/query-pr.cgi?pr=ports/136070
>
> -- 
> Edwin Groothuis via the GNATS Auto Assign Tool
> edwin@FreeBSD.org
>
Comment 9 Wesley Shields freebsd_committer freebsd_triage 2009-07-09 04:15:08 UTC
On Wed, Jul 08, 2009 at 12:35:40AM +0200, Mohacsi Janos wrote:
> Dear FreeBSD commiters,
>  	Here I send the patch for upgrade net-mgmt/nfsen to 1.3.2.
> 
> Janos Mohacsi
> Network Engineer, Research Associate, Head of Network Planning and Projects
> NIIF/HUNGARNET, HUNGARY
> Key 70EF9882: DEC2 C685 1ED4 C95A 145F  4300 6F64 7B00 70EF 9882

Thanks, I'll commit this change in a day or so.

I noticed you're sending this mail from a new address. Would you like me
to update your ports to use this address?

-- WXS
Comment 10 Mohacsi Janos 2009-07-09 10:35:16 UTC
On Wed, 8 Jul 2009, Wesley Shields wrote:

> On Wed, Jul 08, 2009 at 12:35:40AM +0200, Mohacsi Janos wrote:
>> Dear FreeBSD commiters,
>>  	Here I send the patch for upgrade net-mgmt/nfsen to 1.3.2.
>>
>> Janos Mohacsi
>> Network Engineer, Research Associate, Head of Network Planning and Projects
>> NIIF/HUNGARNET, HUNGARY
>> Key 70EF9882: DEC2 C685 1ED4 C95A 145F  4300 6F64 7B00 70EF 9882
>
> Thanks, I'll commit this change in a day or so.
>
> I noticed you're sending this mail from a new address. Would you like me
> to update your ports to use this address?
>

Please do not update the e-mail address. I use the janos.mohacsi@bsd.hu 
alias for *BSD related activities. This is forwarded to my current e-mail 
address.

Best Regards,

 		Janos Mohacsi
Comment 11 Wesley Shields freebsd_committer freebsd_triage 2009-07-10 00:29:56 UTC
State Changed
From-To: analyzed->closed

Committed. Thanks!