Gentoo Archives: gentoo-hardened

From: "Tóth Attila" <atoth@××××××××××.hu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] recent glibc upgrade vs squid/basic_ncsa_auth
Date: Mon, 08 Apr 2013 02:57:56
Message-Id: 1b9f13f363141857c1e9651f472ad701.squirrel@atoth.sote.hu
In Reply to: [gentoo-hardened] recent glibc upgrade vs squid/basic_ncsa_auth by "Tóth Attila"
1 Update:
2 I saw another recent report of the issue:
3 https://bbs.archlinux.org/viewtopic.php?id=158283
4
5 And found this commit:
6 http://pkgs.fedoraproject.org/cgit/squid.git/commit/?id=71ebdc6bb16abe75ff38b7573836d35a20bae880
7 The patch fixes the issue!
8
9 Regards:
10 Dw.
11 --
12 dr Tóth Attila, Radiológus, 06-20-825-8057
13 Attila Toth MD, Radiologist, +36-20-825-8057
14
15 2013.Április 7.(V) 01:34 időpontban "Tóth Attila" ezt írta:
16 > After bumping glibc from 2.16 to 2.17, squid auth stopped working. This is
17 > what I can find in the logs. The issue even triggers the fork detection
18 > which kills squid. The symptoms are the same for 3.8.0-hardened-r1 and
19 > 3.8.5-hardened.
20 >
21 > What else I can do to help diagnose the problem?
22 > Apr 6 23:00:12 kernel: basic_ncsa_auth[2819]: segfault at 0 ip
23 > 000003052a8c112a sp 000003e4a06628c8 error 4 in
24 > libc-2.17.so[3052a79f000+1a2000]
25 > Apr 6 23:00:12 atoth kernel: grsec: Segmentation fault occurred at
26 > (nil) in /usr/libexec/squid/basic_ncsa_auth[basic_ncsa_auth:2819]
27 > uid/euid:31/0 gid/egid:31/31, parent /usr/sbin/squid[squid:2818]
28 > uid/euid:31/31 gid/egid:31/31
29 >
30 > Thanks:
31 > Dwokfur
32 > --
33 > dr Tóth Attila, Radiológus, 06-20-825-8057
34 > Attila Toth MD, Radiologist, +36-20-825-8057
35 >
36 >
37 >