Your message dated Thu, 21 Apr 2011 01:55:22 +0000
with message-id <e1qcj74-0000ah...@franck.debian.org>
and subject line Bug#621493: fixed in tinyproxy 1.8.2-1squeeze1
has caused the Debian Bug report #621493,
regarding tinyproxy: allows everyone if using network addresses in Allow rule
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
621493: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=621493
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: tinyproxy
Version: 1.8.2-1
Severity: grave
Tags: upstream security squeeze patch
Justification: user security hole
When including a line like
Allow 192.168.0.0/16
to allow a network of ip addresses instead of only one ip
address per line the access to tinyproxy
is actually allowed for all ip addresses.
This makes tinyproxy usable as an open proxy from everywhere
in the internet.
This bug was reported upstream nearly a year ago:
https://banu.com/bugzilla/show_bug.cgi?id=90
and includes a fix there.
Christoph Martin
-- System Information:
Debian Release: 6.0.1
APT prefers stable
APT policy: (900, 'stable'), (90, 'oldstable'), (70, 'testing')
Architecture: amd64 (x86_64)
Kernel: Linux 2.6.32-5-amd64 (SMP w/2 CPU cores)
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)
Shell: /bin/sh linked to /bin/bash
Versions of packages tinyproxy depends on:
ii libc6 2.11.2-10 Embedded GNU C Library: Shared lib
ii logrotate 3.7.8-6 Log rotation utility
tinyproxy recommends no packages.
tinyproxy suggests no packages.
-- Configuration Files:
/etc/tinyproxy.conf changed:
User nobody
Group nogroup
Port 8888
Timeout 600
DefaultErrorFile "/usr/share/tinyproxy/default.html"
StatFile "/usr/share/tinyproxy/stats.html"
Logfile "/var/log/tinyproxy/tinyproxy.log"
LogLevel Info
PidFile "/var/run/tinyproxy/tinyproxy.pid"
MaxClients 100
MinSpareServers 5
MaxSpareServers 20
StartServers 10
MaxRequestsPerChild 0
Allow 127.0.0.1
ViaProxyName "tinyproxy"
ConnectPort 443
ConnectPort 563
-- no debconf information
--- End Message ---
--- Begin Message ---
Source: tinyproxy
Source-Version: 1.8.2-1squeeze1
We believe that the bug you reported is fixed in the latest version of
tinyproxy, which is due to be installed in the Debian FTP archive:
tinyproxy_1.8.2-1squeeze1.debian.tar.bz2
to main/t/tinyproxy/tinyproxy_1.8.2-1squeeze1.debian.tar.bz2
tinyproxy_1.8.2-1squeeze1.dsc
to main/t/tinyproxy/tinyproxy_1.8.2-1squeeze1.dsc
tinyproxy_1.8.2-1squeeze1_amd64.deb
to main/t/tinyproxy/tinyproxy_1.8.2-1squeeze1_amd64.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 621...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Jordi Mallach <jo...@debian.org> (supplier of updated tinyproxy package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Tue, 19 Apr 2011 10:05:41 +0200
Source: tinyproxy
Binary: tinyproxy
Architecture: source amd64
Version: 1.8.2-1squeeze1
Distribution: stable-security
Urgency: low
Maintainer: Ed Boraas <e...@debian.org>
Changed-By: Jordi Mallach <jo...@debian.org>
Description:
tinyproxy - A lightweight, non-caching, optionally anonymizing http proxy
Closes: 621493
Changes:
tinyproxy (1.8.2-1squeeze1) stable-security; urgency=low
.
* Add netmask_generation.patch: fix bug in ACL netmask generation,
which could allow to use Tinyproxy as an open proxy very easily
[CVE-2011-1499] (closes: #621493).
Checksums-Sha1:
5b03e7bfc3b640e273d826f84c8bcf5d8b3b20dd 1295 tinyproxy_1.8.2-1squeeze1.dsc
6e1ce865e82ad07e540be89d5e6c6bc75489d42b 202931 tinyproxy_1.8.2.orig.tar.bz2
950ff865a37a2a0d5f6b0aeb967bafce1a39b684 12472
tinyproxy_1.8.2-1squeeze1.debian.tar.bz2
6ffeea5eaea4d581db94d2ce8ebd8e86a2da200a 86462
tinyproxy_1.8.2-1squeeze1_amd64.deb
Checksums-Sha256:
b7b093488f7a83b5f0580b92bbb23d9c14cef0805c37a468f52369f44f58c147 1295
tinyproxy_1.8.2-1squeeze1.dsc
7e9b831f40c4497db114c4edbf3300976e66ab7a47c2f42de8345c103c92f838 202931
tinyproxy_1.8.2.orig.tar.bz2
f4d6939dd831a211042b3a933109bec7890ba7776ffad68d8bde580e0b3d1257 12472
tinyproxy_1.8.2-1squeeze1.debian.tar.bz2
ceb8309a27e318e8a6c1edc0c4bb6d822f304bc52b80dcf501192d88ee2c511b 86462
tinyproxy_1.8.2-1squeeze1_amd64.deb
Files:
b1a385f396e2aa9e6f962e456aa4506d 1295 web optional
tinyproxy_1.8.2-1squeeze1.dsc
edc8502193cfed4974d6a770da173755 202931 web optional
tinyproxy_1.8.2.orig.tar.bz2
e626dbc16fdd69bb7ebb99f7f3c96044 12472 web optional
tinyproxy_1.8.2-1squeeze1.debian.tar.bz2
e70ef24ae2b14ea1045c9a264aca5417 86462 web optional
tinyproxy_1.8.2-1squeeze1_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
iEYEARECAAYFAk2uGccACgkQJYSUupF6Il7K/QCfZl7zBF8p9OCwGFPGJh6Pc5Uw
6h4AoJecMPcTjlv+1RFLQOZEu5hF49SF
=giVF
-----END PGP SIGNATURE-----
--- End Message ---