Bug 197844 - www/fcgi issue (CVE-2012-6687)
Summary: www/fcgi issue (CVE-2012-6687)
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Many People
Assignee: Rodrigo Osorio
URL:
Keywords: patch, patch-ready
Depends on:
Blocks:
 
Reported: 2015-02-20 10:29 UTC by Rodrigo Osorio
Modified: 2015-03-05 22:44 UTC (History)
1 user (show)

See Also:
freebsd: maintainer-feedback+


Attachments
update fcgi to 2.4.0_5 + CVE patch (3.43 KB, patch)
2015-02-20 10:29 UTC, Rodrigo Osorio
no flags Details | Diff
CVE patch + cpe records (3.70 KB, patch)
2015-02-20 13:58 UTC, Rodrigo Osorio
koobs: maintainer-approval+
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Rodrigo Osorio freebsd_committer freebsd_triage 2015-02-20 10:29:38 UTC
Created attachment 153202 [details]
update fcgi to 2.4.0_5 + CVE patch

Yesterday was released the CVE-2012-6687[1] who report possible DOS attacks
allowed by fastcgi 2.4.0. As far as I can see, it's our version in ports.

Attached a patch integrate the fix :
https://launchpadlibrarian.net/93064712/poll.patch


[1] http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-6687
Comment 1 Bugzilla Automation freebsd_committer freebsd_triage 2015-02-20 10:29:38 UTC
Maintainer CC'd
Comment 3 A.J. "Fonz" van Werven 2015-02-20 12:45:59 UTC
Thanks for reporting! I'll look into this ASAP (hopefully today, no later than tomorrow).
Comment 4 Rodrigo Osorio freebsd_committer freebsd_triage 2015-02-20 13:58:43 UTC
Created attachment 153215 [details]
CVE patch + cpe records

I change my patch to take advantage of this update
to add CPE informations to www/fcgi.

Here are the details about what the CPE is : https://wiki.freebsd.org/Ports/CPE

Cheers
- rodrigo
Comment 5 A.J. "Fonz" van Werven 2015-02-20 14:16:40 UTC
According to the Wiki, adding CPE records is mandatory in this case. Thanks for the update.

I've verified that the patch builds. And the code looks OK too, so I've set maintainer approval. Feel free to poke a committer if you don't have the necessary bit(s) yourself.
Comment 6 Rodrigo Osorio freebsd_committer freebsd_triage 2015-02-20 14:39:06 UTC
Don't worry, I have the required bits :)
I'm now preparing the vuxml record.
Comment 7 Rodrigo Osorio freebsd_committer freebsd_triage 2015-03-04 08:31:30 UTC
ping
Comment 8 A.J. "Fonz" van Werven 2015-03-04 11:15:36 UTC
It was ready to be committed last time, or did I miss something?
Comment 9 Kubilay Kocak freebsd_committer freebsd_triage 2015-03-04 11:17:39 UTC
Reporter is Committer
Comment 10 Kubilay Kocak freebsd_committer freebsd_triage 2015-03-04 11:18:11 UTC
Comment on attachment 153215 [details]
CVE patch + cpe records

Just for reference maintainer-feedback is not maintainer-approval. Setting maintainer-approval on the attachment/patch for clarity
Comment 11 A.J. "Fonz" van Werven 2015-03-04 14:10:22 UTC
Ah, that must have been my bad then. Sorry for the inconvenience.
Comment 12 commit-hook freebsd_committer freebsd_triage 2015-03-04 23:32:44 UTC
A commit references this bug:

Author: rodrigo
Date: Wed Mar  4 23:31:58 UTC 2015
New revision: 380457
URL: https://svnweb.freebsd.org/changeset/ports/380457

Log:
  Patch fcgi to address CVE-2012-6687 vulnerabilities.

  PR:		197844
  Submitted by:	rodrigo
  Obtained from:	ubuntu
  MFH:		2015Q1
  Security:	CVE-2012-6687

Changes:
  head/www/fcgi/Makefile
  head/www/fcgi/files/patch-CVE-2012-6687-pool
Comment 13 Rodrigo Osorio freebsd_committer freebsd_triage 2015-03-04 23:33:15 UTC
committed, thanks
Comment 14 commit-hook freebsd_committer freebsd_triage 2015-03-05 22:44:28 UTC
A commit references this bug:

Author: rodrigo
Date: Thu Mar  5 22:44:26 UTC 2015
New revision: 380562
URL: https://svnweb.freebsd.org/changeset/ports/380562

Log:
  MFH: r380457

  Patch fcgi to address CVE-2012-6687 vulnerabilities.

  PR:		197844
  Submitted by:	rodrigo
  Obtained from:	ubuntu
  Security:	CVE-2012-6687
  Approved by:	ports-secteam

Changes:
_U  branches/2015Q1/
  branches/2015Q1/www/fcgi/Makefile
  branches/2015Q1/www/fcgi/files/patch-CVE-2012-6687-pool