Community Packages

Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines

Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.

REPEAT: Do NOT report bugs for outdated packages!
Tasklist

FS#47967 - [opensmtpd] smtpd segfaults since uptdate to openssl 1.0.2f

Attached to Project: Community Packages
Opened by Holger Obermaier (holgerob) - Sunday, 31 January 2016, 16:34 GMT
Last edited by Doug Newgard (Scimmia) - Thursday, 14 April 2016, 13:55 GMT
Task Type Bug Report
Category Packages
Status Closed
Assigned To Lukas Fleischer (lfleischer)
Architecture All
Severity Medium
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 1
Private No

Details

After updating openssl to 1.0.2f smtpd segfaults when ever an encrypted connection is established:
{{{
dmesg
...
[32867.976503] smtpd[477]: segfault at 0 ip (null) sp 00007fffcc05c288 error 14 in smtpd[400000+6d000]
...
}}}

{{{
journalctl -b --unit smtpd.service
...
Jan 31 09:53:09 holgerserver smtpd[18326]: smtp-in: session 4d926814df2b8788: connection from host mout.web.de [212.227.15.4] established
Jan 31 09:53:09 holgerserver systemd[1]: smtpd.service: Main process exited, code=exited, status=1/FAILURE
Jan 31 09:53:09 holgerserver systemd[1]: smtpd.service: Unit entered failed state.
Jan 31 09:53:09 holgerserver systemd[1]: smtpd.service: Failed with result 'exit-code'.
...
Jan 31 13:27:45 holgerserver smtpd[20563]: smtp-in: session 502de5eca7395cc7: connection from host mout.web.de [212.227.17.12] established
Jan 31 13:27:45 holgerserver smtpd[20564]: warn: ca -> pony: pipe closed
Jan 31 13:27:45 holgerserver smtpd[20562]: warn: scheduler -> control: pipe closed
Jan 31 13:27:45 holgerserver smtpd[20559]: warn: queue -> control: pipe closed
Jan 31 13:27:45 holgerserver smtpd[20558]: warn: parent -> control: pipe closed
Jan 31 13:27:45 holgerserver systemd[1]: smtpd.service: Main process exited, code=exited, status=1/FAILURE
Jan 31 13:27:45 holgerserver systemd[1]: smtpd.service: Unit entered failed state.
Jan 31 13:27:45 holgerserver systemd[1]: smtpd.service: Failed with result 'exit-code'.
}}}

This task depends upon

Closed by  Doug Newgard (Scimmia)
Thursday, 14 April 2016, 13:55 GMT
Reason for closing:  Fixed
Additional comments about closing:  5.7.3p2-1
Comment by Björn Schümann (bjoerns2000) - Sunday, 31 January 2016, 22:27 GMT Comment by Bruno Pagani (ArchangeGabriel) - Monday, 01 February 2016, 16:20 GMT
Exact same issue here. Severity is critical I think: you have either no mail server or must run a two known CVEs openssl…

Also, what upstream do we need to report? ssl or OpenSMTPd? The later one I suppose?
Comment by Björn Schümann (bjoerns2000) - Monday, 01 February 2016, 19:48 GMT
OpenSMTPD has an issue about the problem:
https://github.com/OpenSMTPD/OpenSMTPD/issues/650
Comment by Wilhelm Schuster (wlhlm) - Tuesday, 02 February 2016, 14:26 GMT
The update to 5.7.3p2 has been released to address the issue.

See http://thread.gmane.org/gmane.mail.opensmtpd.general/3280
Comment by Lukas Fleischer (lfleischer) - Thursday, 14 April 2016, 05:36 GMT
Is this fixed in 5.7.3p2-3?
Comment by Bruno Pagani (ArchangeGabriel) - Thursday, 14 April 2016, 10:19 GMT
Is has been fixed since 5.7.3p2-1, thanks. You can close.

Loading...