bad timestamp parsing

Bug #1178281 reported by Francois Trahan
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
fwlogwatch (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Log line matching does not account for the fact that for small kernel timestamps, there can be space at the beginning of the stamp.

Marking as security as not having a proper report of blocked connexions reduces auditing capacities

Here is an example of a log line that would not work, because of the space in the timestamp "[ 1690.227087]"

Apr 18 18:05:37 rack1 kernel: [ 1690.227087] fw: IN= OUT=eth0 SRC=166.78.158.192 DST=72.14.183.239 LEN=76 TOS=0x00 PREC=0xC0 TTL=64 ID=0 DF PROTO=UDP
SPT=123 DPT=123 LEN=56

have fun,
Frank

ProblemType: Bug
DistroRelease: Ubuntu 12.04
Package: fwlogwatch 1.2-2
ProcVersionSignature: Ubuntu 3.2.0-41.66-generic 3.2.42
Uname: Linux 3.2.0-41-generic x86_64
NonfreeKernelModules: nvidia
ApportVersion: 2.0.1-0ubuntu17.2
Architecture: amd64
CheckboxSubmission: 07acc21e2cd262f4bfdaa4e25a19f966
CheckboxSystem: 2a6f54df59af338184485e85cbcf0d32
Date: Thu May 9 10:13:33 2013
InstallationMedia: Ubuntu 10.10 "Maverick Meerkat" - Release amd64 (20101007)
MarkForUpload: True
ProcEnviron:
 TERM=xterm
 PATH=(custom, no user)
 LANG=en_CA.UTF-8
 SHELL=/bin/bash
SourcePackage: fwlogwatch
UpgradeStatus: Upgraded to precise on 2012-06-05 (337 days ago)
mtime.conffile..etc.fwlogwatch.fwlogwatch.config: 2013-05-06T16:41:50.186316

Revision history for this message
Francois Trahan (francois-trahan) wrote :
Revision history for this message
Francois Trahan (francois-trahan) wrote :

I have a patch that fixes it, at least for netfilter.

Can anyone help me have it hit the repos ?

Revision history for this message
Francois Trahan (francois-trahan) wrote :

Here's my patch.

information type: Private Security → Public Security
Revision history for this message
Ubuntu Foundations Team Bug Bot (crichton) wrote :

The attachment "patch" seems to be a patch. If it isn't, please remove the "patch" flag from the attachment, remove the "patch" tag, and if you are a member of the ~ubuntu-reviewers, unsubscribe the team.

[This is an automated message performed by a Launchpad user owned by ~brian-murray, for any issues please contact him.]

tags: added: patch
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures

Changed in fwlogwatch (Ubuntu):
status: New → Incomplete
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package fwlogwatch - 1.2-2ubuntu0.12.10.1

---------------
fwlogwatch (1.2-2ubuntu0.12.10.1) quantal-security; urgency=low

  * SECURITY UPDATE: log messages near boot were missed (LP: #1178281)
    - netfilter.l: update timestamp regular expression, thanks to Francois
      Trahan for the patch.
 -- Seth Arnold <email address hidden> Thu, 09 May 2013 18:35:20 -0700

Changed in fwlogwatch (Ubuntu):
status: Incomplete → Fix Released
Revision history for this message
Seth Arnold (seth-arnold) wrote :

8.04 LTS's fwlogwatch appears to lack the necessary routines to parse this style of log; I've not prepared an update for it. If you wish to prepare a debdiff to support this logging format on 8.04 LTS, that's welcomed, but may require going through the SRU process rather than a simple security update.

Thanks

Revision history for this message
Seth Arnold (seth-arnold) wrote :

I gave the log sample, this bug URL, and your patch URL, to the upstream author. I didn't patch Saucy under the assumption a new version would come from Debian in the next few months. You might wish to keep an eye on that.

Thanks

Revision history for this message
Colin Watson (cjwatson) wrote :

I've copied this update forward to saucy.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Patches

Remote bug watches

Bug watches keep track of this bug in other bug trackers.