Skip to Content.
Sympa Menu

devel - [Sami Haahtinen <ressu@debian.org>] Bug#100486: sympa: possible DOS with sympa

Subject: Developers of Sympa

List archive

Chronological Thread  
  • From: address@concealed (Jérôme Marant)
  • To: address@concealed
  • Subject: [Sami Haahtinen <address@concealed>] Bug#100486: sympa: possible DOS with sympa
  • Date: 11 Jun 2001 16:02:39 +0200


Here is a bug report I received to today. I don't know if it applies to
newer versions of sympa but if it does, it should be fixed as soon as
possible.

Cheers,

--- Begin Message ---
  • From: Sami Haahtinen <address@concealed>
  • To: Debian Bug Tracking System <address@concealed>
  • Subject: Bug#100486: sympa: possible DOS with sympa
  • Date: Mon, 11 Jun 2001 11:50:15 +0300
  • Resent-cc: Jerome Marant <address@concealed>
  • Resent-date: Mon, 11 Jun 2001 08:48:20 GMT
  • Resent-from: Sami Haahtinen <address@concealed>
  • Resent-to: address@concealed
Package: sympa
Version: 2.6.1-3
Severity: grave

so far i have found 2 files which cause sympa to just hang, it will not
respond to incoming mail or anything else before these mails are removed from
queue.

here is the log sympa provides.
--Snip--
moonlit:/var/spool/sympa/queue# sympa -d -F
Configuration file read
Using locale file us.cat version 2.5.4
NLS message file version 2.5.4 different from src version 2.6.1
Sympa 2.6.1 Started
Sympa 2.6.1 Started
List object taimipotti created
Reaper unwaited pids :
Open = 0
Processing /var/spool/sympa/queue/taimipotti.992185356.9908 with priority 5
--Snap--

here are the headers of the mail in question.

--Snip--
X-Sympa-To: taimipotti
Return-Path: <address@concealed>
Delivered-To: address@concealed
Received: from smtp.dave.sonera.fi (smtp.dave.sonera.fi [131.177.130.21])
by moonlit.uusikaupunki.fi (Postfix) with ESMTP id 4270D23F82
for <address@concealed>; Sun, 10 Jun 2001 18:02:36
+0300 (EEST)
Received: from muuli.mv.sonera.fi ([194.137.238.208]:4104 "EHLO
muuli.vallila.sonera.fi") by inside.dave.sonera.fi with ESMTP
id <S57006AbRFJPAY>; Sun, 10 Jun 2001 18:00:24 +0300
Received: from sonera.com (dial-b-197.valpa.sonera.fi [131.177.117.197])
by muuli.vallila.sonera.fi (8.8.8/8.8.6) with ESMTP id RAA12690
for <address@concealed>; Sun, 10 Jun 2001 17:58:34
+0300 (EETDST)
Message-ID: <address@concealed>
Date: Sun, 10 Jun 2001 17:56:49 +0300
From: Oili Kaijomaa <address@concealed>
X-Mailer: Mozilla 4.7 [en] (Win98; I)
X-Accept-Language: en
MIME-Version: 1.0
To: address@concealed
Subject: Re: [Taimipotti] =?iso-8859-1?Q?=23=A4=25=26=25=A4=25=23?="
Meconopsis!!
References: <006201c0ee86$8a5f3ea0$6631fea9@iin-seutu>
<015401c0ee94$4e69c920$8c6297d4@ast> <address@concealed>
<014401c0ef62$7ffe9c80$9e2697d4@ast>
<002501c0efd8$dc304820$0100a8c0@kanetti347>
<address@concealed>
<00fd01c0f054$1a81b0c0$ac1e97d4@ast>
<address@concealed>
<006701c0f0f6$eed484e0$0100a8c0@kanetti347>
<address@concealed>
<address@concealed>
<address@concealed>
<address@concealed>
Content-Type: multipart/alternative;
boundary="------------D6DB8576F6E81605EC4B7BC7"
--Snip--

apparently the problem lies in the perl Mail::Header library, but sympa should
be able to identify the problem and ignore mails like this.

(i suspect that the header in question is References, for being too long.. or
Sibject for containing umlauts.)

Sami

-- System Information
Debian Release: 2.2
Architecture: i386
Kernel: Linux moonlit 2.4.3 #2 SMP Tue Apr 17 16:19:04 EEST 2001 i686

Versions of packages sympa depends on:
ii libc6 2.1.3-18 GNU C Library: Shared libraries
an
ii libdigest-md5-perl 2.09-1 MD5 Message Digest for Perl

ii libio-stringy-perl 1.207-3 Perl5 modules for IO from
scalars
ii libmime-base64-perl 2.11-2 MIME/Base64 decoding for Perl

ii libmime-perl 4.121-2.1 Perl5 modules for MIME-compliant
m
ii libmsgcat-perl 1.01-3 Locale::Msgcat perl module

ii mailtools 1.13-4 Manipulate email in perl
programs
ii perl-5.005 [perl5] 5.005.03-7.1 Larry Wall's Practical
Extracting
ii postfix 0.0.19991231pl11-1 A mail transport agent

ii sysklogd 1.3-33.1 Kernel and system logging
daemons

-- Configuration Files:
/etc/sympa/sympa.conf changed:
home /var/spool/sympa/expl
etc /etc/sympa
pidfile /var/spool/sympa/sympa.pid
umask 027
syslog `/bin/cat /etc/sympa/facility`
log_socket_type unix
nrcpt 40
avg 10
maxsmtp 50
sendmail /usr/sbin/sendmail
host `/bin/cat /etc/mailname || /bin/hostname -f`
listmaster `echo -n listmaster@; /bin/cat /etc/mailname || /bin/hostname
-f`
cookie `/bin/cat /etc/sympa/cookie`
email sympa
msgcat /usr/lib/sympa/nls
lang us
queue /var/spool/sympa/queue
clean_delay_queue 1
queuedigest /var/spool/sympa/queuedigest
queuemod /var/spool/sympa/queuemod
clean_delay_queuemod 10
queueauth /var/spool/sympa/queueauth
clean_delay_queueauth 3

queueexpire /var/spool/sympa/queueexpire
queuebounce /var/spool/sympa/queuebounce
queueoutgoing /var/spool/sympa/queueoutgoing
sleep 5






--- End Message ---


--
Jérôme Marant <address@concealed>

-----------------------------------------------------------
| IDEALX - Open Source Engineering / Ingénierie Open Source |
| http://IDEALX.com |
-----------------------------------------------------------



Archive powered by MHonArc 2.6.19+.

Top of Page