[Bug 506710] New: racoon doesn't start and reports stack smashing attempt
http://bugzilla.novell.com/show_bug.cgi?id=506710 Summary: racoon doesn't start and reports stack smashing attempt Classification: openSUSE Product: openSUSE 11.1 Version: Final Platform: i586 OS/Version: Other Status: NEW Severity: Critical Priority: P5 - None Component: Network AssignedTo: bnc-team-screening@forge.provo.novell.com ReportedBy: lukasz.stelmach@iem.pw.edu.pl QAContact: qa@suse.de Found By: --- Created an attachment (id=294058) --> (http://bugzilla.novell.com/attachment.cgi?id=294058) my racoon configuration that causes crash User-Agent: Mozilla/5.0 (X11; U; Linux x86_64; pl-PL; rv:1.9.0.7) Gecko/2009030810 Iceweasel/3.0.9 (Debian-3.0.9-1) Racoon crashes if I use the attached configuration. It doesn't if I remove the sainfo section from the racoon.conf file. I run updated openSUSE 11.1. Reproducible: Always Steps to Reproduce: 1. Use attached configuration files. 2. Run racoon: racoon -d -F -6 -f /etc/racoon/racoon.conf 3. Watch it crashing Actual Results: Foreground mode. 2009-05-23 15:43:55: INFO: @(#)ipsec-tools 0.7.1 (http://ipsec-tools.sourceforge.net) 2009-05-23 15:43:55: INFO: @(#)This product linked OpenSSL 0.9.8h 28 May 2008 (http://www.openssl.org/) 2009-05-23 15:43:55: INFO: Reading configuration from "/etc/racoon/racoon.conf" 2009-05-23 15:43:55: DEBUG: call pfkey_send_register for AH 2009-05-23 15:43:55: DEBUG: call pfkey_send_register for ESP 2009-05-23 15:43:55: DEBUG: call pfkey_send_register for IPCOMP 2009-05-23 15:43:55: INFO: Resize address pool from 0 to 255 2009-05-23 15:43:55: DEBUG: reading config file /etc/racoon/racoon.conf *** stack smashing detected ***: racoon terminated ======= Backtrace: ========= /lib/libc.so.6(__fortify_fail+0x48)[0xb7c90db8] /lib/libc.so.6(__fortify_fail+0x0)[0xb7c90d70] racoon[0x807d29b] racoon[0x8092fde] racoon[0x809d2ba] racoon[0x809d7e8] racoon[0x804cd0d] /lib/libc.so.6(__libc_start_main+0xe5)[0xb7bc0705] racoon[0x804c8c1] ======= Memory map: ======== 08048000-080d4000 r-xp 00000000 fd:00 313126 /usr/sbin/racoon 080d4000-080d5000 r--p 0008b000 fd:00 313126 /usr/sbin/racoon 080d5000-080d6000 rw-p 0008c000 fd:00 313126 /usr/sbin/racoon 080d6000-080fd000 rw-p 080d6000 00:00 0 [heap] b7b15000-b7b22000 r-xp 00000000 fd:00 426303 /lib/libgcc_s.so.1 b7b22000-b7b23000 r--p 0000c000 fd:00 426303 /lib/libgcc_s.so.1 b7b23000-b7b24000 rw-p 0000d000 fd:00 426303 /lib/libgcc_s.so.1 b7b32000-b7b34000 rw-p b7b32000 00:00 0 b7b34000-b7b3b000 r-xp 00000000 fd:00 262828 /usr/lib/libkrb5support.so.0.1 b7b3b000-b7b3c000 r--p 00006000 fd:00 262828 /usr/lib/libkrb5support.so.0.1 b7b3c000-b7b3d000 rw-p 00007000 fd:00 262828 /usr/lib/libkrb5support.so.0.1 b7b3d000-b7b55000 r-xp 00000000 fd:00 426241 /lib/libaudit.so.0.0.0 b7b55000-b7b56000 r--p 00018000 fd:00 426241 /lib/libaudit.so.0.0.0 b7b56000-b7b57000 rw-p 00019000 fd:00 426241 /lib/libaudit.so.0.0.0 b7b57000-b7b58000 rw-p b7b57000 00:00 0 b7b58000-b7b8f000 r-xp 00000000 fd:00 426225 /lib/libncurses.so.5.6 b7b8f000-b7b91000 r--p 00036000 fd:00 426225 /lib/libncurses.so.5.6 b7b91000-b7b95000 rw-p 00038000 fd:00 426225 /lib/libncurses.so.5.6 b7b95000-b7ba8000 r-xp 00000000 fd:00 426227 /lib/libz.so.1.2.3 b7ba8000-b7ba9000 r--p 00012000 fd:00 426227 /lib/libz.so.1.2.3 b7ba9000-b7baa000 rw-p 00013000 fd:00 426227 /lib/libz.so.1.2.3 b7baa000-b7cff000 r-xp 00000000 fd:00 426205 /lib/libc-2.9.so b7cff000-b7d00000 ---p 00155000 fd:00 426205 /lib/libc-2.9.so b7d00000-b7d02000 r--p 00155000 fd:00 426205 /lib/libc-2.9.so b7d02000-b7d03000 rw-p 00157000 fd:00 426205 /lib/libc-2.9.so b7d03000-b7d06000 rw-p b7d03000 00:00 0 b7d06000-b7d09000 r-xp 00000000 fd:00 426208 /lib/libdl-2.9.so b7d09000-b7d0a000 r--p 00002000 fd:00 426208 /lib/libdl-2.9.so b7d0a000-b7d0b000 rw-p 00003000 fd:00 426208 /lib/libdl-2.9.so b7d0b000-b7d1d000 r-xp 00000000 fd:00 426220 /lib/libresolv-2.9.so b7d1d000-b7d1e000 r--p 00011000 fd:00 426220 /lib/libresolv-2.9.so b7d1e000-b7d1f000 rw-p 00012000 fd:00 426220 /lib/libresolv-2.9.so b7d1f000-b7d22000 rw-p b7d1f000 00:00 0 b7d22000-b7d24000 r-xp 00000000 fd:00 426240 /lib/libkeyutils-1.2.so b7d24000-b7d25000 r--p 00001000 fd:00 426240 /lib/libkeyutils-1.2.so b7d25000-b7d26000 rw-p 00002000 fd:00 426240 /lib/libkeyutils-1.2.so b7d26000-b7d28000 r-xp 00000000 fd:00 426305 /lib/libcom_err.so.2.1 b7d28000-b7d29000 r--p 00001000 fd:00 426305 /lib/libcom_err.so.2.1 b7d29000-b7d2a000 rw-p 00002000 fd:00 426305 /lib/libcom_err.so.2.1 b7d2a000-b7d4e000 r-xp 00000000 fd:00 262822 /usr/lib/libk5crypto.so.3.1 b7d4e000-b7d4f000 r--p 00024000 fd:00 262822 /usr/lib/libk5crypto.so.3.1 b7d4f000-b7d50000 rw-p 00025000 fd:00 262822 /usr/lib/libk5crypto.so.3.1 b7d50000-b7dec000 r-xp 00000000 fd:00 262827 /usr/lib/libkrb5.so.3.3 b7dec000-b7dee000 r--p 0009b000 fd:00 262827 /usr/lib/libkrb5.so.3.3 b7dee000-b7def000 rw-p 0009d000 fd:00 262827 /usr/lib/libkrb5.so.3.3 b7def000-b7e1a000 r-xp 00000000 fd:00 262820 /usr/lib/libgssapi_krb5.so.2.2 b7e1a000-b7e1b000 r--p 0002a000 fd:00 262820 /usr/lib/libgssapi_krb5.so.2.2 b7e1b000-b7e1c000 rw-p 0002b000 fd:00 262820 /usr/lib/libgssapi_krb5.so.2.2 b7e1c000-b7e27000 r-xp 00000000 fd:00 426309 /lib/libpam.so.0.81.12 b7e27000-b7e28000 r--p 0000a000 fd:00 426309 /lib/libpam.so.0.81.12 b7e28000-b7e29000 rw-p 0000b000 fd:00 426309 /lib/libpam.so.0.81.12 b7e29000-b7e2a000 rw-p b7e29000 00:00 0 b7e2a000-b7e38000 r-xp 00000000 fd:00 426207 /lib/libcrypt-2.9.so b7e38000-b7e39000 r--p 0000d000 fd:00 4Aborted Expected Results: Racoon running. -- Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=506710 User lukasz.stelmach@iem.pw.edu.pl added comment http://bugzilla.novell.com/show_bug.cgi?id=506710#c1 --- Comment #1 from Łukasz Stelmach <lukasz.stelmach@iem.pw.edu.pl> 2009-05-23 08:32:09 MDT --- It seems there is similar bug in Ubuntu (https://bugs.launchpad.net/ubuntu/+source/ipsec-tools/+bug/374185). However a computer of mine with Debian-testing aboard works ok with the same configuration files. -- Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=506710 User lukasz.stelmach@iem.pw.edu.pl added comment http://bugzilla.novell.com/show_bug.cgi?id=506710#c2 --- Comment #2 from Łukasz Stelmach <lukasz.stelmach@iem.pw.edu.pl> 2009-05-23 14:03:17 MDT --- Created an attachment (id=294066) --> (http://bugzilla.novell.com/attachment.cgi?id=294066) a fix for buffer overflow in ipsecdoi_id2str() The patch fixes a buffer overflow (!!!) in ipsecdoi_id2str() function by replacing sockaddr with sockaddr_storage. It might be usefull to look for other sockaddrs that cannot hold IPv6. -- Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=506710 Marcus Meissner <meissner@novell.com> changed: What |Removed |Added ---------------------------------------------------------------------------- AssignedTo|bnc-team-screening@forge.pr |jbohac@novell.com |ovo.novell.com | -- Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=506710 User jbohac@novell.com added comment http://bugzilla.novell.com/show_bug.cgi?id=506710#c3 Jiri Bohac <jbohac@novell.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED Resolution| |FIXED --- Comment #3 from Jiri Bohac <jbohac@novell.com> 2009-06-11 10:59:26 MDT --- I just submitted a fixed package to openSUSE:11.0, openSUSE:11.1 and SLE-11, together with fixes for Bug#504186 and Bug #498859. I also submitted a fixed package to Factory. I a different patch, found in the CVS: http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/ipsec_doi.c.diff?r1=1.36&r2=1.37&f=h&f=u Thanks! -- Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=506710 User swamp@suse.com added comment http://bugzilla.novell.com/show_bug.cgi?id=506710#c4 Swamp Workflow Management <swamp@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status Whiteboard| |maint:released:10.3:25288 | |maint:released:11.0:25288 | |maint:released:11.1:25288 --- Comment #4 from Swamp Workflow Management <swamp@suse.com> 2009-06-24 05:09:01 MDT --- Update released for: ipsec-tools, ipsec-tools-debuginfo, ipsec-tools-debugsource Products: openSUSE 10.3 (i386, ppc, x86_64) openSUSE 11.0 (debug, i386, ppc, x86_64) openSUSE 11.1 (debug, i586, ppc, x86_64) -- Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=506710 User swamp@suse.com added comment http://bugzilla.novell.com/show_bug.cgi?id=506710#c5 Swamp Workflow Management <swamp@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status Whiteboard|maint:released:10.3:25288 |maint:released:10.3:25288 |maint:released:11.0:25288 |maint:released:11.0:25288 |maint:released:11.1:25288 |maint:released:11.1:25288 | |maint:released:sle11:25285 --- Comment #5 from Swamp Workflow Management <swamp@suse.com> 2009-06-24 16:08:28 MDT --- Update released for: ipsec-tools, ipsec-tools-debuginfo, ipsec-tools-debugsource Products: SLE-DEBUGINFO 11 (i386, ia64, ppc64, s390x, x86_64) SLE-SERVER 11 (i386, ia64, ppc64, s390x, x86_64) -- Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=506710 User swamp@suse.com added comment http://bugzilla.novell.com/show_bug.cgi?id=506710#c6 Swamp Workflow Management <swamp@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status Whiteboard|maint:released:10.3:25288 |maint:released:10.3:25288 |maint:released:11.0:25288 |maint:released:11.0:25288 |maint:released:11.1:25288 |maint:released:11.1:25288 |maint:released:sle11:25285 |maint:released:sles9:25287 | |maint:released:sles9-sld:25 | |287 --- Comment #6 from Swamp Workflow Management <swamp@suse.com> 2009-06-24 16:08:35 MDT --- Update released for: ipsec-tools Products: Novell-Linux-Desktop 9 (i386, x86_64) Novell-Linux-POS 9 (i386) Open-Enterprise-Server 9 (i386) SUSE-CORE 9 (i386, ia64, ppc, s390, s390x, x86_64) -- Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=506710 User swamp@suse.com added comment http://bugzilla.novell.com/show_bug.cgi?id=506710#c7 Swamp Workflow Management <swamp@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status Whiteboard|maint:released:10.3:25288 |maint:released:10.3:25288 |maint:released:11.0:25288 |maint:released:11.0:25288 |maint:released:11.1:25288 |maint:released:11.1:25288 |maint:released:sles9:25287 |maint:released:sle10-sp2:25 |maint:released:sles9-sld:25 |286 |287 | --- Comment #7 from Swamp Workflow Management <swamp@suse.com> 2009-06-24 16:08:53 MDT --- Update released for: ipsec-tools Products: SLE-DEBUGINFO 10-SP2 (i386, ia64, ppc, s390x, x86_64) SLE-SDK 10-SP2 (i386, ia64, ppc, s390x, x86_64) SLE-SERVER 10-SP2 (i386, ia64, ppc, s390x, x86_64) -- Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=506710 User swamp@suse.com added comment http://bugzilla.novell.com/show_bug.cgi?id=506710#c8 Swamp Workflow Management <swamp@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status Whiteboard|maint:released:10.3:25288 |maint:released:10.3:25288 |maint:released:11.0:25288 |maint:released:11.0:25288 |maint:released:11.1:25288 |maint:released:11.1:25288 |maint:released:sle10-sp2:25 |maint:released:sle10-sp2:25 |286 |286 | |maint:released:sle11:25311 --- Comment #8 from Swamp Workflow Management <swamp@suse.com> 2009-06-30 16:08:30 MDT --- Update released for: novell-ipsec-tools, novell-ipsec-tools-debuginfo, novell-ipsec-tools-debugsource, novell-ipsec-tools-devel Products: SLE-DEBUGINFO 11 (i386, x86_64) SLE-DESKTOP 11 (i386, x86_64) SLE-SDK 11 (i386, x86_64) -- Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=506710 User swamp@suse.com added comment http://bugzilla.novell.com/show_bug.cgi?id=506710#c9 Swamp Workflow Management <swamp@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status Whiteboard|maint:released:10.3:25288 |maint:released:10.3:25288 |maint:released:11.0:25288 |maint:released:11.0:25288 |maint:released:11.1:25288 |maint:released:11.1:25288 |maint:released:sle10-sp2:25 |maint:released:sle10-sp2:25 |286 |286 |maint:released:sle11:25311 |maint:released:sle11:25311 | |maint:released:10.3:25313 | |maint:released:11.0:25313 | |maint:released:11.1:25313 --- Comment #9 from Swamp Workflow Management <swamp@suse.com> 2009-07-01 00:39:45 MDT --- Update released for: novell-ipsec-tools, novell-ipsec-tools-debuginfo, novell-ipsec-tools-debugsource, novell-ipsec-tools-devel Products: openSUSE 10.3 (i386, ppc, x86_64) openSUSE 11.0 (debug, i386, ppc, x86_64) openSUSE 11.1 (debug, i586, ppc, x86_64) -- Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=506710 User swamp@suse.com added comment http://bugzilla.novell.com/show_bug.cgi?id=506710#c10 Swamp Workflow Management <swamp@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status Whiteboard|maint:released:10.3:25288 |maint:released:10.3:25288 |maint:released:11.0:25288 |maint:released:11.0:25288 |maint:released:11.1:25288 |maint:released:11.1:25288 |maint:released:sle10-sp2:25 |maint:released:sle10-sp2:25 |286 |286 |maint:released:sle11:25311 |maint:released:sle11:25311 |maint:released:10.3:25313 |maint:released:10.3:25313 |maint:released:11.0:25313 |maint:released:11.0:25313 |maint:released:11.1:25313 |maint:released:11.1:25313 | |maint:released:sle10-sp2:25 | |312 --- Comment #10 from Swamp Workflow Management <swamp@suse.com> 2009-07-01 16:09:35 MDT --- Update released for: novell-ipsec-tools, novell-ipsec-tools-devel Products: SLE-DEBUGINFO 10-SP2 (i386, ia64, ppc, s390x, x86_64) SLE-DESKTOP 10-SP2 (i386, x86_64) SLE-SDK 10-SP2 (i386, ia64, ppc, s390x, x86_64) -- Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=506710 http://bugzilla.novell.com/show_bug.cgi?id=506710#c11 --- Comment #11 from Bernhard Wiedemann <bwiedemann@suse.com> --- This is an autogenerated message for OBS integration: This bug (506710) was mentioned in https://build.opensuse.org/request/show/11885 11.0 / ipsec-tools https://build.opensuse.org/request/show/11886 11.1 / ipsec-tools https://build.opensuse.org/request/show/11893 Factory / ipsec-tools -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com