As far as I can tell, this is a security issue since fail2ban and
presumably other monitoring daemons will silently ignore intrusion
attempts on Precise server (see bug #954453).

Apart from breaking intrusion detection, it turns out this issue with
gamin was also the cause of delayed IMAP mail notifications with
postfix/dovecot and loss of nightly backups on our server following an
upgrade to Precise.

The problem is due to a deadlock after the first disconnect from
gam_server under common conditions.

https://bugzilla.gnome.org/show_bug.cgi?id=667230 has the correct fix
for this issue which should be applied in Ubuntu and uploaded to
precise-security as soon as possible.

Gentoo is using this fix (http://sources.gentoo.org/cgi-
bin/viewvc.cgi/gentoo-x86/app-admin/gam-server/files/gam-server-0.1.10
-ih_sub_cancel-deadlock.patch?revision=1.1) while Fedora is using a
similar but less accurate version
(https://bugzilla.redhat.com/show_bug.cgi?id=786170).

Would be great to set this up so it monitors the other trackers as the
problem was fixed in other distributions months ago yet the latest
Ubuntu release didn't get the fix. I don't know my way around Launchpad
well enough to do that myself.


** Bug watch added: Red Hat Bugzilla #786170
   https://bugzilla.redhat.com/show_bug.cgi?id=786170

** This bug has been flagged as a security vulnerability

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/926862

Title:
  python-gamin does not detect any filesystem events

To manage notifications about this bug go to:
https://bugs.launchpad.net/gamin/+bug/926862/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to