Comment 5 for bug 926862

Revision history for this message
alp (atoker) wrote :

As far as I can tell, this is a security issue since fail2ban and presumably other monitoring daemons will silently ignore intrusion attempts on Precise server (see bug #954453).

Apart from breaking intrusion detection, it turns out this issue with gamin was also the cause of delayed IMAP mail notifications with postfix/dovecot and loss of nightly backups on our server following an upgrade to Precise.

The problem is due to a deadlock after the first disconnect from gam_server under common conditions.

https://bugzilla.gnome.org/show_bug.cgi?id=667230 has the correct fix for this issue which should be applied in Ubuntu and uploaded to precise-security as soon as possible.

Gentoo is using this fix (http://sources.gentoo.org/cgi-bin/viewvc.cgi/gentoo-x86/app-admin/gam-server/files/gam-server-0.1.10-ih_sub_cancel-deadlock.patch?revision=1.1) while Fedora is using a similar but less accurate version (https://bugzilla.redhat.com/show_bug.cgi?id=786170).

Would be great to set this up so it monitors the other trackers as the problem was fixed in other distributions months ago yet the latest Ubuntu release didn't get the fix. I don't know my way around Launchpad well enough to do that myself.