Debian Bug report logs - #584929
znc: segfault under certain conditions

version graph

Package: znc; Maintainer for znc is Patrick Matthäi <pmatthaei@debian.org>; Source for znc is src:znc.

Reported by: Suschman <reportbug.10.suschman@spamgourmet.com>

Date: Mon, 7 Jun 2010 16:15:01 UTC

Severity: grave

Tags: security

Found in versions znc/0.090~rc1-1, znc/0.058-2+lenny3

Fixed in versions znc/0.090-2, znc/0.058-2+lenny4

Done: Patrick Matthäi <pmatthaei@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, reportbug.10.suschman@spamgourmet.com, Patrick Matthäi <pmatthaei@debian.org>:
Bug#584929; Package znc. (Mon, 07 Jun 2010 16:15:04 GMT) Full text and rfc822 format available.

Acknowledgement sent to Suschman <reportbug.10.suschman@spamgourmet.com>:
New Bug report received and forwarded. Copy sent to reportbug.10.suschman@spamgourmet.com, Patrick Matthäi <pmatthaei@debian.org>. (Mon, 07 Jun 2010 16:15:04 GMT) Full text and rfc822 format available.

Message #5 received at submit@bugs.debian.org (full text, mbox):

From: Suschman <reportbug.10.suschman@spamgourmet.com>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: znc: segfault under certain conditions
Date: Mon, 07 Jun 2010 18:11:15 +0200
Package: znc
Version: 0.090~rc1-1
Severity: grave
Justification: renders package unusable

After updating 0.080-1 to 0.090-rc1-1 znc segfaults. This happens for instance when klicking "traffic" in the webadmin pages or issuing the traffic command on the /znc shell. May happen under other conditions aswell.
Znc -D does not provide usfull output other then the segfault message direktly after rescieve of the mentioned command.

-- System Information:
Debian Release: squeeze/sid
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: i386 (i686)

Kernel: Linux 2.6.18-ovz028stab039.1-smp (SMP w/2 CPU cores)
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)
Shell: /bin/sh linked to /bin/dash

Versions of packages znc depends on:
ii  libc-ares2                    1.7.1-0    library for asyncronous name resol
ii  libc6                         2.10.2-9   Embedded GNU C Library: Shared lib
ii  libgcc1                       1:4.4.4-1  GCC support library
ii  libssl0.9.8                   0.9.8n-1   SSL shared libraries
ii  libstdc++6                    4.4.4-1    The GNU Standard C++ Library v3

Versions of packages znc recommends:
ii  znc-extra                    0.090~rc1-1 extra modules for znc
pn  znc-perl                     <none>      (no description available)
pn  znc-tcl                      <none>      (no description available)

znc suggests no packages.

-- no debconf information




Information forwarded to debian-bugs-dist@lists.debian.org, Patrick Matthäi <pmatthaei@debian.org>:
Bug#584929; Package znc. (Mon, 07 Jun 2010 18:18:03 GMT) Full text and rfc822 format available.

Acknowledgement sent to pmatthaei@debian.org:
Extra info received and forwarded to list. Copy sent to Patrick Matthäi <pmatthaei@debian.org>. (Mon, 07 Jun 2010 18:18:03 GMT) Full text and rfc822 format available.

Message #10 received at 584929@bugs.debian.org (full text, mbox):

From: Patrick Matthäi <pmatthaei@debian.org>
To: Suschman <reportbug.10.suschman@spamgourmet.com>, 584929@bugs.debian.org
Subject: Re: Bug#584929: znc: segfault under certain conditions
Date: Mon, 07 Jun 2010 20:15:17 +0200
Am 07.06.2010 18:11, schrieb Suschman:
> Package: znc
> Version: 0.090~rc1-1
> Severity: grave
> Justification: renders package unusable
>
> After updating 0.080-1 to 0.090-rc1-1 znc segfaults. This happens for instance when klicking "traffic" in the webadmin pages or issuing the traffic command on the /znc shell. May happen under other conditions aswell.
> Znc -D does not provide usfull output other then the segfault message direktly after rescieve of the mentioned command.
>

Do you get a useful output with `gdb znc' if you install znc-dbg?

-- 
/*
Mit freundlichem Gruß / With kind regards,
 Patrick Matthäi
 GNU/Linux Debian Developer

E-Mail: pmatthaei@debian.org
        patrick@linux-dev.org

Comment:
Always if we think we are right,
we were maybe wrong.
*/




Reply sent to Patrick Matthäi <pmatthaei@debian.org>:
You have taken responsibility. (Mon, 14 Jun 2010 16:37:04 GMT) Full text and rfc822 format available.

Notification sent to Suschman <reportbug.10.suschman@spamgourmet.com>:
Bug acknowledged by developer. (Mon, 14 Jun 2010 16:37:04 GMT) Full text and rfc822 format available.

Message #15 received at 584929-close@bugs.debian.org (full text, mbox):

From: Patrick Matthäi <pmatthaei@debian.org>
To: 584929-close@bugs.debian.org
Subject: Bug#584929: fixed in znc 0.090-2
Date: Mon, 14 Jun 2010 16:34:24 +0000
Source: znc
Source-Version: 0.090-2

We believe that the bug you reported is fixed in the latest version of
znc, which is due to be installed in the Debian FTP archive:

znc-dbg_0.090-2_amd64.deb
  to main/z/znc/znc-dbg_0.090-2_amd64.deb
znc-dev_0.090-2_amd64.deb
  to main/z/znc/znc-dev_0.090-2_amd64.deb
znc-extra_0.090-2_amd64.deb
  to main/z/znc/znc-extra_0.090-2_amd64.deb
znc-perl_0.090-2_amd64.deb
  to main/z/znc/znc-perl_0.090-2_amd64.deb
znc-tcl_0.090-2_amd64.deb
  to main/z/znc/znc-tcl_0.090-2_amd64.deb
znc_0.090-2.debian.tar.gz
  to main/z/znc/znc_0.090-2.debian.tar.gz
znc_0.090-2.dsc
  to main/z/znc/znc_0.090-2.dsc
znc_0.090-2_amd64.deb
  to main/z/znc/znc_0.090-2_amd64.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 584929@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Patrick Matthäi <pmatthaei@debian.org> (supplier of updated znc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Mon, 14 Jun 2010 18:05:43 +0200
Source: znc
Binary: znc znc-extra znc-dbg znc-dev znc-perl znc-tcl
Architecture: source amd64
Version: 0.090-2
Distribution: unstable
Urgency: high
Maintainer: Patrick Matthäi <pmatthaei@debian.org>
Changed-By: Patrick Matthäi <pmatthaei@debian.org>
Description: 
 znc        - an advanced IRC bouncer
 znc-dbg    - an advanced IRC bouncer (debugging symbols)
 znc-dev    - an advanced IRC bouncer (development headers)
 znc-extra  - extra modules for znc
 znc-perl   - an advanced IRC bouncer (Perl extension)
 znc-tcl    - an advanced IRC bouncer (Tcl extension)
Closes: 584929
Changes: 
 znc (0.090-2) unstable; urgency=high
 .
   * Add patch 01-null-pointer-traffic.diff, which fixes a NULL pointer
     dereference in the traffic stats.
     Closes: #584929
Checksums-Sha1: 
 c318dcd3497962e2d33b7a0c969bbc79c796d59e 1109 znc_0.090-2.dsc
 d9b90d9d2a8e770ce8a22064eaada2dd6656c5ca 11395 znc_0.090-2.debian.tar.gz
 3f3a6164e7aa87ca0db33d0a1a1ff55ba3cff1f6 1315510 znc_0.090-2_amd64.deb
 84de249bb3d3910e88355ad0373a88a1d5513271 270156 znc-extra_0.090-2_amd64.deb
 21077dc32d3bbd29cefa8365be6fd3b745ad8395 7458632 znc-dbg_0.090-2_amd64.deb
 a0ce4eb34f85697c43d9b5f2d73221c5042e57a0 65394 znc-dev_0.090-2_amd64.deb
 29b82cca95e54c0a8547ab4239148c5559ead928 65094 znc-perl_0.090-2_amd64.deb
 4c702cb23dbf3230d54efb4d07c474a766a74b1c 35656 znc-tcl_0.090-2_amd64.deb
Checksums-Sha256: 
 9ea9ec105e1826848c2f59c3d5bcc36fc959e54c1a00601371d5387407d63aa0 1109 znc_0.090-2.dsc
 8b84a479c06acd0532bfad6a28f6b97660292eade8d41086938922cbc562fc89 11395 znc_0.090-2.debian.tar.gz
 14c658d714df8d7d91b541753810f5c51bd4cdfe81fb85a37c1298e744fc5ed3 1315510 znc_0.090-2_amd64.deb
 a60da5f401170c589c32376780ba61edbbb24b48d6f4ff29f770b10545941bcd 270156 znc-extra_0.090-2_amd64.deb
 650bdc1ed493d58f88415956600d284845aa00a538b01df35ed469cca799d5ff 7458632 znc-dbg_0.090-2_amd64.deb
 7964949e3b4b9f2ff899a6c3c59aaba4af6c061172a306847b13110114968043 65394 znc-dev_0.090-2_amd64.deb
 e794be31b31eb93de77bd5e36abd4029bc545f0463e644d7f659cd7f176cf1b7 65094 znc-perl_0.090-2_amd64.deb
 8fde9a92bf64512d79af6b3bbf95e158a0e9e62fe1acbaea58702c9dd685505f 35656 znc-tcl_0.090-2_amd64.deb
Files: 
 b9269a63a92f8eb395487c52215af000 1109 net optional znc_0.090-2.dsc
 310cf662f11c29ad1447f01b8e75b7c7 11395 net optional znc_0.090-2.debian.tar.gz
 50aea7ab1b63a8c9770f59d714a05aa1 1315510 net optional znc_0.090-2_amd64.deb
 1770aade0677035372463533e270429a 270156 net optional znc-extra_0.090-2_amd64.deb
 13b4bfcd705f58d664c81c98dd732575 7458632 debug extra znc-dbg_0.090-2_amd64.deb
 d2eb3711568d9bb1805f991da116d9a4 65394 net optional znc-dev_0.090-2_amd64.deb
 9de8c829731331172579437a4a193f45 65094 net optional znc-perl_0.090-2_amd64.deb
 aa3f40801bf53e6bc4cf5a365fefa985 35656 net optional znc-tcl_0.090-2_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkwWVY0ACgkQ2XA5inpabMdcDQCfczwBUKBOY33kUBCV0r3wo/eq
o10An3ppQ7eI3ti7K5KeTaGoLd87OE+G
=/gCw
-----END PGP SIGNATURE-----





Information forwarded to debian-bugs-dist@lists.debian.org, Patrick Matthäi <pmatthaei@debian.org>:
Bug#584929; Package znc. (Mon, 14 Jun 2010 16:57:06 GMT) Full text and rfc822 format available.

Acknowledgement sent to pmatthaei@debian.org:
Extra info received and forwarded to list. Copy sent to Patrick Matthäi <pmatthaei@debian.org>. (Mon, 14 Jun 2010 16:57:06 GMT) Full text and rfc822 format available.

Message #20 received at 584929@bugs.debian.org (full text, mbox):

From: Patrick Matthäi <pmatthaei@debian.org>
To: Debian Bug Control <control@bugs.debian.org>, 584929@bugs.debian.org
Subject: found in stable
Date: Mon, 14 Jun 2010 18:53:30 +0200
found #584929 0.058-2+lenny3
tags #584929 security
thanks

-- 
/*
Mit freundlichem Gruß / With kind regards,
 Patrick Matthäi
 GNU/Linux Debian Developer

E-Mail: pmatthaei@debian.org
        patrick@linux-dev.org

Comment:
Always if we think we are right,
we were maybe wrong.
*/




Bug Marked as found in versions znc/0.058-2+lenny3. Request was from Patrick Matthäi <pmatthaei@debian.org> to control@bugs.debian.org. (Mon, 14 Jun 2010 16:57:07 GMT) Full text and rfc822 format available.

Added tag(s) security. Request was from Patrick Matthäi <pmatthaei@debian.org> to control@bugs.debian.org. (Mon, 14 Jun 2010 16:57:08 GMT) Full text and rfc822 format available.

Reply sent to Patrick Matthäi <pmatthaei@debian.org>:
You have taken responsibility. (Mon, 12 Jul 2010 13:57:09 GMT) Full text and rfc822 format available.

Notification sent to Suschman <reportbug.10.suschman@spamgourmet.com>:
Bug acknowledged by developer. (Mon, 12 Jul 2010 13:57:09 GMT) Full text and rfc822 format available.

Message #29 received at 584929-close@bugs.debian.org (full text, mbox):

From: Patrick Matthäi <pmatthaei@debian.org>
To: 584929-close@bugs.debian.org
Subject: Bug#584929: fixed in znc 0.058-2+lenny4
Date: Mon, 12 Jul 2010 13:55:59 +0000
Source: znc
Source-Version: 0.058-2+lenny4

We believe that the bug you reported is fixed in the latest version of
znc, which is due to be installed in the Debian FTP archive:

znc_0.058-2+lenny4.diff.gz
  to main/z/znc/znc_0.058-2+lenny4.diff.gz
znc_0.058-2+lenny4.dsc
  to main/z/znc/znc_0.058-2+lenny4.dsc
znc_0.058-2+lenny4_i386.deb
  to main/z/znc/znc_0.058-2+lenny4_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 584929@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Patrick Matthäi <pmatthaei@debian.org> (supplier of updated znc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Mon, 14 Jun 2010 19:06:57 +0200
Source: znc
Binary: znc
Architecture: source i386
Version: 0.058-2+lenny4
Distribution: stable-security
Urgency: high
Maintainer: Patrick Matthäi <pmatthaei@debian.org>
Changed-By: Patrick Matthäi <pmatthaei@debian.org>
Description: 
 znc        - advanced modular IRC bouncer
Closes: 584929
Changes: 
 znc (0.058-2+lenny4) stable-security; urgency=high
 .
   * Add patch 05-null-pointer-traffic.dpatch, which fixes an NULL pointer
     dereference with traffic stats. znc crashs, if someone requests traffic
     statistics, while there was an unauthenticated connection to znc.
     Closes: #584929
Checksums-Sha1: 
 34bed5d442c408e94157fd96cb58ef656e29c1b8 1038 znc_0.058-2+lenny4.dsc
 147c6b09693b4ca3892a27a151ea5a1480d84ad7 9957 znc_0.058-2+lenny4.diff.gz
 427626c7fe451dc50de896d9e399ffbb3a0dedc5 1012740 znc_0.058-2+lenny4_i386.deb
Checksums-Sha256: 
 9a350afd34ce7d4dea214cb63d6402c3acf4f3847207a9cc502a42736f38d4a3 1038 znc_0.058-2+lenny4.dsc
 ec151be19664b06d8f128fcc6cedd6abea42bf5e8600ac4a05d6e904d0dd5c87 9957 znc_0.058-2+lenny4.diff.gz
 c28a05fb9689196d5918fe63caa1d9ccaf17bd1bbaffe0bcbf860a550bed4907 1012740 znc_0.058-2+lenny4_i386.deb
Files: 
 46f176d6370f395b9166832d839f667c 1038 net optional znc_0.058-2+lenny4.dsc
 f83f0daa62de96ddd125a57e355997f7 9957 net optional znc_0.058-2+lenny4.diff.gz
 8e9428972501db9a05d6f8012a1b58c2 1012740 net optional znc_0.058-2+lenny4_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkwsT1cACgkQ2XA5inpabMdmCwCfViQuUcqFqd2UKvgEqc/J1Ma2
KOwAn2sileAGeEzKJLx1GW1blcl4p0eD
=1C5I
-----END PGP SIGNATURE-----





Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 05 Sep 2010 07:33:46 GMT) Full text and rfc822 format available.

Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Mon Apr 21 13:25:03 2014; Machine Name: beach.debian.org

Debian Bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.