Bug#643336: libgcrypt11: New 1.5.0 version segfaults with NSS/PAM LDAP

Andreas Metzler ametzler at downhill.at.eu.org
Sun Oct 2 06:39:48 UTC 2011


On 2011-09-27 "Marc Dequènes (Duck)" <duck at duckcorp.org> wrote:
> Package: libgcrypt11
> Version: 1.5.0-3
> Severity: important

> Coin,

> I'm using:
>   - libgnutls26  2.12.10-2
>   - libldap-2.4-2  2.4.25-3
>   - libnss-ldap  264-2.2

> After an upgrade a mere "id <user>" lead to the following segfault:
> #0  0xb72011cd in do_aesni_enc_aligned (
>     a=0xb723a1b8 "\001K\257\"x\246\235\063\035Q\200\020\066C\351\232gC\303\321Q\232\264\362͚x\253\t\245\021\275]\036\362\r\316ּ\274\022\023\032\307\305G\210\252\b\016\225\027\353\026wq\232\317r\200\206\004",
> <incomplete sequence \343>, b=0xbfb28ad8
> "(\335%\267p\213\262\277\004{\343\t", ctx=0xbfb288e8) at
> rijndael.c:710
> #1  do_aesni (ctx=0xbfb288e8, decrypt_flag=0, bx=0xbfb28ad8
> "(\335%\267p\213\262\277\004{\343\t",
>     ax=0xb723a1b8 "\001K\257\"x\246\235\063\035Q\200\020\066C\351\232gC\303\321Q\232\264\362͚x\253\t\245\021\275]\036\362\r\316ּ\274\022\023\032\307\305G\210\252\b\016\225\027\353\026wq\232\317r\200\206\004",
> <incomplete sequence \343>) at rijndael.c:1132
> #2  0xb72014c6 in rijndael_encrypt (context=0xbfb288e8, b=0xbfb28ad8
[...]

Hello,

do you also get the segfault when connecting the ldap server with
gnutls-cli? Do I understand correctly that your cpu supports the
AES-NI instruction set? (grep -i aes /proc/cpuinfo)

cu andreas





More information about the Pkg-gnutls-maint mailing list