Solar Designer | 13 Dec 11:12

Re: [Fwd: [RHSA-2002:196-09] Updated xinetd packages fix denial of service vulnerability]

Hi Steve,

Perhaps you're aware of whether this is fixed in development versions
and what the fix was?

On Fri, Dec 13, 2002 at 03:15:33AM +0300, Dmitry V. Levin wrote:
> On Thu, Dec 05, 2002 at 05:09:08PM -0500, Ryan Cleary wrote:
> > On 4 Dec 2002, Dan Rowles wrote:
> [...]
> > Red Hat is using the "epoch" field in the RPM metadata to allow you to
> > automatically "upgrade" (or freshen) from 2.3.9 (epoch 1) back to 2.3.7
> > (epoch 2).
> > 
> > They rolled back to 2.3.7 because 2.3.9 was leaving stale TCP connections 
> > in the CLOSE_WAIT state, according to their bugzilla database:
> > http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=76146 for more info.
> 
> There is a real problem with hanging file descriptors which makes 2.3.9
> unusable on production servers (just tested on ftp.altlinux.com).
> 
> More over, xinetd passes these hundreds of descriptors to spawned children. :(
> 
> Any ideas?
> 
> 
> --
> ldv

--

-- 
/sd
(Continue reading)

Steve G | 13 Dec 15:03
Favicon

Re: [Fwd: [RHSA-2002:196-09] Updated xinetd packages fix denial of service vulnerability]

Hello,

>Perhaps you're aware of whether this is fixed 
>in development versions and what the fix was?

Yes there this was a problem but is now fixed. There
is one other serious problem fixed in the current
development version where descriptors were being
played with fast and loose. It the latter case, xinetd
mixed up its descriptors and sent log entries to
stdout....not good.

RedHat has rolled out 2 updates for xinetd so far and
they will be rolling out another. They are not
coordinating with anyone on the mailing list and I
think they are shooting themselves in the foot badly.
Because they are not coordinating, they are just
grabbing development snapshots that aren't complete or
fully tested.

The current development snapshot 20021209.tar.gz in
the xinetd.org/devel folder is stable and will become
release 2.3.10 in the next day or two. Rob felt like
we could release 2.3.10 this week.

Here's a link to the e-mail that I posted to the group
when I discovered the cause of the leaked descriptors:
http://marc.theaimsgroup.com/?l=xinetd&m=103767881425253&w=2

And here's a link to an e-mail where someone else
(Continue reading)


Gmane