advisory coordination (Re: SA-02:35)

From: Anatole Shaw (shaw@autoloop.com)
Date: 08/06/02


Date: Tue, 6 Aug 2002 05:32:37 -0400
From: Anatole Shaw <shaw@autoloop.com>
To: Dag-Erling Smorgrav <des@ofug.org>

On Tue, Aug 06, 2002 at 01:19:22AM +0200, Dag-Erling Smorgrav wrote:
> Oleg Derevenetz <oleg@vsi.ru> writes:
> > I recently visited ftp.freebsd.org, and found directory SA-02:35 in
> > CERT/patches without corresponding advisory in CERT/advisories.
> SA-02:35 is due out today. We release patches early to make sure
> they've propagated to all the mirrors by the time we release the
> advisory.

In May, I had an exchange with two FreeBSD Security Officers about the
release of advisory SA-02:25, which referenced patches that didn't yet
exist on the FTP site. I recommended that patches and advisories be made
available together. One SO told me that, in the future, patch propagation
would be assured prior to advisory release, but that attaching patches to
advisories was passe.

It seems that this piecemeal bit of change is now in force, with the
obvious results. On or before August 2nd, the same problem occured in
reverse -- a patch for SA-02:35 (the FFS filesize bug) was propagated
without a corresponding advisory, as noted by Oleg above.

As a result, there were just about 3 days during which the security patch
circulated with no explanation. Those were three days for blackhats to
examine the patch, and for exploits to emerge and circulate, before most
admins were aware of the bug or its impact.

On the same day, Ache@ forwarded an unrelated CVS commit on setlocale.c to
this list, adding nonchalantly, "That original BSD code bug can be
exploitable." The advisory for this one is still in the works, I guess.

I'm all for full-disclosure, but something is very wrong in these 2 cases.
Known security problems are being released in fragments without any
coordination. It seems that a basic Vulnerability Coordination function
is broken or missing, and surely we can fix this.

-- 
Anatole Shaw
Autoloop Security Consulting
http://www.autoloop.com
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • Re: sshd patch
    ... > version string still doesn't match the one in the advisory. ... patches can be applied to as many different versions of FreeBSD as ... eyeball inspection of the patch. ... This is generally the case with security advisories, ...
    (freebsd-questions)
  • Re: [FreeBSD-Announce] FreeBSD Security Advisory FreeBSD-SA-06:22.openssh
    ... BTW, the patches for this advisory appear to also need a patch to add log.c into src/secure/usr.sbin/sshd/Makefile. ...
    (FreeBSD-Security)
  • Re: advisory coordination (Re: SA-02:35)
    ... >> is, an incomplete advisory is better than no advisory at all, when bug ... >> details (i.e. patch) are already circulating. ... I didn't mean at all that the quality of the patches should be ... exactly when there is a security risk and what the workarounds might be. ...
    (FreeBSD-Security)
  • Re: [!H] Tcpdump 3.5.2 remote root vulnerability (fwd)
    ... >> This affects our tcpdump. ... I do recall the advisory which mainly patches some calls from sprintf ... to this list patches two calls to sscanf. ...
    (FreeBSD-Security)
  • RE: telnetd root exploit
    ... Until an official advisory is released, does that mean there's no official ... I'm new to patches, and was looking for them on the FTP site, but they are ... > Subject: Re: telnetd root exploit ... > (Yes, I do read the commit messages, but I've been known to miss these ...
    (FreeBSD-Security)