Your message dated Sat, 05 Feb 2005 18:11:58 +0100
with message-id <[EMAIL PROTECTED]>
and subject line Bug#293217: Segmentation fault by /usr/lib/mailman/cron/qrunner
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--------------------------------------
Received: (at submit) by bugs.debian.org; 1 Feb 2005 20:10:57 +0000
>From [EMAIL PROTECTED] Tue Feb 01 12:10:57 2005
Return-path: <[EMAIL PROTECTED]>
Received: from fw.ferraro.net (smtp.trashmail.net) [213.41.144.50] 
        by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
        id 1Cw4MS-0001sD-00; Tue, 01 Feb 2005 12:10:57 -0800
Received: by smtp.trashmail.net (Postfix, from userid 0)
        id E220133C82; Tue,  1 Feb 2005 21:11:19 +0100 (CET)
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: saf <[EMAIL PROTECTED]>
To: Debian Bug Tracking System <[EMAIL PROTECTED]>
Subject: Segmentation fault by /usr/lib/mailman/cron/qrunner
X-Mailer: reportbug 2.56
Date: Tue, 01 Feb 2005 21:11:19 +0100
Message-Id: <[EMAIL PROTECTED]>
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
        (1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-8.0 required=4.0 tests=BAYES_00,HAS_PACKAGE 
        autolearn=no version=2.60-bugs.debian.org_2005_01_02
X-Spam-Level: 

Package: mailman
Version: 2.0.11-1woody8
Severity: critical
Justification: security hole

When I send an email to the mailing list, I get an email from the cronjob:

---------- CUT HERE -----------
>From [EMAIL PROTECTED]  Tue Feb  1 20:57:05 2005
Return-Path: [EMAIL PROTECTED]
X-Original-To: list
Delivered-To: [EMAIL PROTECTED]
Received: by smtp.trashmail.net (Postfix, from userid 38)
        id 8967333C92; Tue,  1 Feb 2005 20:57:05 +0100 (CET)
From: Cron Daemon <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
Subject: Cron <[EMAIL PROTECTED]>    [ -x /usr/bin/python -a -f 
/usr/lib/mailman/cron/qrunner ] && /usr/bin/python
+/usr/lib/mailman/cron/qrunner
X-Cron-Env: <SHELL=/bin/sh>
X-Cron-Env: <HOME=/var/list>
X-Cron-Env: <PATH=/usr/bin:/bin>
X-Cron-Env: <LOGNAME=list>
Message-Id: <[EMAIL PROTECTED]>
Date: Tue,  1 Feb 2005 20:57:05 +0100 (CET)

Segmentation fault

---------- CUT HERE -----------

I don't know where is the error, why it's seg faults, and if it's dangerous.
But I think if the program makes Segmentation fault, it could be a serious 
security hole.
Somebody could get a shell account with the "list" account privileges.


-- System Information:
Debian Release: testing/unstable
Architecture: i386 (i686)
Kernel: Linux 2.4.25
Locale: [EMAIL PROTECTED], [EMAIL PROTECTED]

Versions of packages mailman depends on:
ii  apache [httpd]              1.3.29.0.2-4 Versatile, high-performance HTTP s
ii  cron                        3.0pl1-83    management of regular background p
ii  debconf                     1.4.21       Debian configuration management sy
ii  libc6                       2.3.2.ds1-11 GNU C Library: Shared libraries an
ii  logrotate                   3.6.5-2      Log rotation utility
ii  postfix [mail-transport-age 2.0.16-4     A high-performance mail transport 
ii  python                      2.3.3-7      An interactive high-level object-o

-- debconf information:
* mailman/gate_news: yes

---------------------------------------
Received: (at 293217-done) by bugs.debian.org; 5 Feb 2005 17:12:00 +0000
>From [EMAIL PROTECTED] Sat Feb 05 09:12:00 2005
Return-path: <[EMAIL PROTECTED]>
Received: from vawad.err.no [129.241.93.49] 
        by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
        id 1CxTTT-0000s6-00; Sat, 05 Feb 2005 09:12:00 -0800
Received: from tfheen by vawad.err.no with local (Exim 4.34)
        id 1CxTTS-0008VI-CZ; Sat, 05 Feb 2005 18:11:58 +0100
To: [EMAIL PROTECTED] (saf)
Cc: [EMAIL PROTECTED]
Subject: Re: Bug#293217: Segmentation fault by /usr/lib/mailman/cron/qrunner
Mail-Copies-To: never
References: <[EMAIL PROTECTED]>
        <[EMAIL PROTECTED]> <[EMAIL PROTECTED]>
From: Tollef Fog Heen <[EMAIL PROTECTED]>
Organization: Private
Date: Sat, 05 Feb 2005 18:11:58 +0100
In-Reply-To: <[EMAIL PROTECTED]> ([EMAIL PROTECTED]'s message of
 "Sat, 5 Feb 2005 17:21:30 +0100")
Message-ID: <[EMAIL PROTECTED]>
User-Agent: Gnus/5.1007 (Gnus v5.10.7) Emacs/21.3 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
        (1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-6.0 required=4.0 tests=BAYES_00,HAS_BUG_NUMBER 
        autolearn=no version=2.60-bugs.debian.org_2005_01_02
X-Spam-Level: 

*  (saf)

| I can no more reproduce the segmentation fault. It has dispeared
| from one day to another. I don't understand it.  I can send you
| always my mailman dir if you like, but please tell me the URL of the
| Debian keyring, I don't find it on their site.

If the segfault has disappeared, I'm just going to close this bug.  I
would advise you to check your system with memtest86 or a simliar
tool, since this can be a hardware problem.

-- 
Tollef Fog Heen                                                        ,''`.
UNIX is user friendly, it's just picky about who its friends are      : :' :
                                                                      `. `' 
                                                                        `-  


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to