mail-notification crashes on SSL connections (patch attached)

Bug #1069886 reported by Jargon Scott
22
This bug affects 2 people
Affects Status Importance Assigned to Milestone
mail-notification (Ubuntu)
Fix Released
High
Gunnar Hjalmarsson
Quantal
Fix Released
High
Gunnar Hjalmarsson

Bug Description

[Impact]
The version of mail-notification shipped with Quantal, 5.4.dfsg.1-6ubuntu4, crashes when using SSL to connect to an IMAP or POP server. The possibility to use SSL is essential, and many users consider this package useless if SSL is broken.

[Test Case]
$ mail-notification
*** stack smashing detected ***: mail-notification terminated
Aborted

[Regression Potential]
The regression risk is minimal.
* The change does not affect any other package.
* I (jarglpa) have tested and confirmed that this patch solves the problem
  for me when applied against mail-notification 5.4.dfsg.1-6ubuntu4.
* I (gunnarhj) have used mail-notification including the bug fix for a few
  weeks, and have not observed any adverse effects.

[Other Info]
This bug was previously fixed for Fedora by Erik van Pienbroek; see Fedora bug #810054. Attached is a copy of Erik van Pienbroek's Fedora patch, which was used to fix this bug in Raring.

Revision history for this message
Jargon Scott (jarglpa) wrote :
Revision history for this message
Ubuntu Foundations Team Bug Bot (crichton) wrote :

The attachment "prevent-stack-overflow-in-verify-ssl-certificate-function.patch" of this bug report has been identified as being a patch. The ubuntu-reviewers team has been subscribed to the bug report so that they can review the patch. In the event that this is in fact not a patch you can resolve this situation by removing the tag 'patch' from the bug report and editing the attachment so that it is not flagged as a patch. Additionally, if you are member of the ubuntu-reviewers team please also unsubscribe the team from this bug report.

[This is an automated message performed by a Launchpad user owned by Brian Murray. Please contact him regarding any issues with the action taken in this bug report.]

tags: added: patch
Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in mail-notification (Ubuntu):
status: New → Confirmed
Revision history for this message
Gunnar Hjalmarsson (gunnarhj) wrote :

I can also confirm that the patch works. In order to possibly speed up the process, I applied the patch in a merge proposal. ;-)

Changed in mail-notification (Ubuntu):
assignee: nobody → Gunnar Hjalmarsson (gunnarhj)
status: Confirmed → In Progress
Revision history for this message
Sebastien Bacher (seb128) wrote :

Uploaded to raring, it would be good to SRU it to quantal, does one of you want to do the SRU work (https://wiki.ubuntu.com/StableReleaseUpdates)? It basically means added those infos to the bug: impact, test case, regression potential and then doing an upload to quantal-proposed with the same changes that went to raring

Changed in mail-notification (Ubuntu):
importance: Undecided → High
Changed in mail-notification (Ubuntu Quantal):
importance: Undecided → High
status: New → Triaged
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package mail-notification - 5.4.dfsg.1-6ubuntu5

---------------
mail-notification (5.4.dfsg.1-6ubuntu5) raring; urgency=low

  * debian/patches/ssh-issue.patch:
    Prevent crashes when using SSL to connect to an IMAP or POP server
    (LP: #1069886). Thanks to Jargon Scott for providing the solution!
 -- Gunnar Hjalmarsson <email address hidden> Fri, 26 Oct 2012 00:26:00 +0200

Changed in mail-notification (Ubuntu):
status: In Progress → Fix Released
description: updated
Changed in mail-notification (Ubuntu Quantal):
assignee: nobody → Gunnar Hjalmarsson (gunnarhj)
status: Triaged → In Progress
Revision history for this message
Sebastien Bacher (seb128) wrote :

sponsored to quantal

Revision history for this message
Chris Halse Rogers (raof) wrote : Please test proposed package

Hello Jargon, or anyone else affected,

Accepted mail-notification into quantal-proposed. The package will build now and be available at http://launchpad.net/ubuntu/+source/mail-notification/5.4.dfsg.1-6ubuntu4.1 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation how to enable and use -proposed. Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please change the bug tag from verification-needed to verification-done. If it does not, change the tag to verification-failed. In either case, details of your testing will help us make a better decision.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

Changed in mail-notification (Ubuntu Quantal):
status: In Progress → Fix Committed
tags: added: verification-needed
Revision history for this message
Gunnar Hjalmarsson (gunnarhj) wrote :

I have installed mail-notification 5.4.dfsg.1-6ubuntu4.1 from quantal-proposed and run it successfully. It fixes this bug as intended.

tags: added: verification-done
removed: verification-needed
Revision history for this message
Jargon Scott (jarglpa) wrote :

Thanks, Chris, Gunnar, & Sebastien.

Like Gunnar, I have also tested mail-notification 5.4.dfsg.1-6ubuntu4.1 from quantal-proposed. I confirm that it's working correctly for me and that the problem behavior is gone.

Revision history for this message
Scott Kitterman (kitterman) wrote : Update Released

The verification of this Stable Release Update has completed successfully and the package has now been released to -updates. Subsequently, the Ubuntu Stable Release Updates Team is being unsubscribed and will not receive messages about this bug report. In the event that you encounter a regression using the package from -updates please report a new bug using ubuntu-bug and tag the bug report regression-update so we can easily find any regresssions.

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package mail-notification - 5.4.dfsg.1-6ubuntu4.1

---------------
mail-notification (5.4.dfsg.1-6ubuntu4.1) quantal-proposed; urgency=low

  * debian/patches/ssh-issue.patch:
    Prevent crashes when using SSL to connect to an IMAP or POP server
    (LP: #1069886). Thanks to Jargon Scott for providing the solution!
 -- Gunnar Hjalmarsson <email address hidden> Sun, 11 Nov 2012 02:26:00 +0100

Changed in mail-notification (Ubuntu Quantal):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.