Your message dated Fri, 02 Nov 2012 09:47:45 +0000
with message-id <[email protected]>
and subject line Bug#692103: fixed in pgbouncer 1.5.2-4
has caused the Debian Bug report #692103,
regarding pgbouncer: add_database: fail gracefully if too long db name
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
692103: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=692103
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: pgbouncer
Version: 1.5.2-1
Severity: grave
Tags: security

pgbouncer 1.5.3-1 in experimental fixes a DoS situation where large
database names can lead to server shutdown.

http://git.postgresql.org/gitweb/?p=pgbouncer.git;a=commitdiff;h=4b92112b820830b30cd7bc91bef3dd8f35305525

add_database: fail gracefully if too long db name

author Marko Kreen <[email protected]>
 Mon, 10 Sep 2012 10:07:43 +0000 (13:07 +0300)

Truncating & adding can lead to fatal() later.

It was not an issue before, but with audodb (* in [databases] section)
the database name can some from network, thus allowing remote shutdown..

src/objects.c

diff --git a/src/objects.c b/src/objects.c
index 3aeb36e..b61387f 100644 (file)
--- a/src/objects.c
+++ b/src/objects.c
@@ -303,7 +303,11 @@ PgDatabase *add_database(const char *name)
                        return NULL;
 
                list_init(&db->head);
-               safe_strcpy(db->name, name, sizeof(db->name));
+               if (strlcpy(db->name, name, sizeof(db->name)) >= 
sizeof(db->name)) {
+                       log_warning("Too long db name: %s", name);
+                       slab_free(db_cache, db);
+                       return NULL;
+               }
                put_in_order(&db->head, &database_list, cmp_database);
        }
 

Thanks to Markus Wanner for helping investigating the issue.

Christoph
-- 
[email protected] | http://www.df7cb.de/

Attachment: signature.asc
Description: Digital signature


--- End Message ---
--- Begin Message ---
Source: pgbouncer
Source-Version: 1.5.2-4

We believe that the bug you reported is fixed in the latest version of
pgbouncer, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Christoph Berg <[email protected]> (supplier of updated pgbouncer package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Fri, 02 Nov 2012 10:05:27 +0100
Source: pgbouncer
Binary: pgbouncer
Architecture: source amd64
Version: 1.5.2-4
Distribution: unstable
Urgency: medium
Maintainer: Christoph Berg <[email protected]>
Changed-By: Christoph Berg <[email protected]>
Description: 
 pgbouncer  - lightweight connection pooler for PostgreSQL
Closes: 692103
Changes: 
 pgbouncer (1.5.2-4) unstable; urgency=medium
 .
   * Cherry-pick from 1.5.3:  Closes: #692103.
     
http://git.postgresql.org/gitweb/?p=pgbouncer.git;a=commitdiff;h=4b92112b820830b30cd7bc91bef3dd8f35305525
     Thanks to Markus Wanner for helping fix this.
 .
     = Critical fix =
     * Too long database names can lead to crash, which
       is remotely triggerable if autodbs are enabled.
 .
       The original checks assumed all names come from config files,
       thus using fatal() was fine, but when autodbs are enabled
       - by '*' in [databases] section - the database name can come
       from network thus making remote shutdown possible.
Checksums-Sha1: 
 597fe8fb1dac2f98c38ca1f0d31a6c0811e99ecf 1999 pgbouncer_1.5.2-4.dsc
 a8bf08382ef8b6e876538fdf6124ba4103ad374d 7275 pgbouncer_1.5.2-4.debian.tar.gz
 e483a6ad763a008927f87f8f2628c3fd2afd2458 150598 pgbouncer_1.5.2-4_amd64.deb
Checksums-Sha256: 
 1a5dfc1e806b81f56d95e0fdbbe054ac85bd24083b14c99a5ced706a8babdc01 1999 
pgbouncer_1.5.2-4.dsc
 6f78ceeb86889dfe1646269e4ea70e752944a389b37d4bac97f7c86dbed68e16 7275 
pgbouncer_1.5.2-4.debian.tar.gz
 7f05d6c80af84526cba319a154d31431c6661b4323bfa3fac990211e38472d14 150598 
pgbouncer_1.5.2-4_amd64.deb
Files: 
 77b1ff143f58478239a4bac3d0418e46 1999 database optional pgbouncer_1.5.2-4.dsc
 6b45a0392a6c22e1f3b6f67fc18ba094 7275 database optional 
pgbouncer_1.5.2-4.debian.tar.gz
 3480cf4748173f480976c37807d28f78 150598 database optional 
pgbouncer_1.5.2-4_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBCAAGBQJQk5UgAAoJEExaa6sS0qeuovYP/3mJtoqJ8XoFS2AjwhXTLOKo
g7RPnuw4TFwP6Pv7mo5hWNQKrDtFOuljw/5gVEEHuN64AsdPahlvCJrii0CKdzrv
/1PAU60ixKb2aHgvXii2+cdbGRQjb6Ntj/+JEUG8Z7YqQkNXdx1m5JnFZlo9DR/m
qrl5h8Pk9k8ccNapatucUpECYo4xDTTlq18xFKZAFNa83s5AEgiYhZFlMN5o1hEk
BsYGZxhoAnmyDD+vEZxFSPlcQVrGTvzGjVckjAPT9F2BJrRvE3WGQC7DKRi3oOR3
FpO5L5sKs0cdltHP4l5COm7eZySnmbNPVGWfNJZKiy16Rp543BPrRBJr03N49dx7
f882hK1eqn5R4H7skZ4Q89lIXr9sTHVr6G/Upw4d8QRpfaF4ut1x3D5c61DeliJ1
0HgRkGHC0r2RrnTa4J5IYuq3qsFMFNZXqFVrF/tFqA0AqLm5dhtJ+I47d/5bEIQq
lQrujJcVaSJAb9pxXiw+tgdyhpICX9yX+5Hjr6o/d/NiZLJPhstdyuzzMe7N9Wwp
aOLSIyaRp2spc4Wtr47L+k/J0jtXlt3goexZl5wJxo8jjHaAzZjQS8SIZTEenEYn
LJBoOeRcLa5BEbRrvfAAxXqzVxup3juD97bkfIQSFTPsn/1y7VpBNZPD39fVTOkl
pouZhcaPHH0TB7hguXMM
=TBGL
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to