NTP rule uses CUPS port

Bug #1388422 reported by Kai Henningsen
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Gufw
Fix Released
Undecided
Unassigned
gui-ufw (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

GUFW comes with a number of default service definitions. The one for NTP mistakenly uses the port from CUPS (631) instead of NTP (123). Obviously, this can lead to misconfigured firewalls, and thus to unsuspected security problems.

ProblemType: Bug
DistroRelease: Ubuntu 14.04
Package: gufw 14.04.2-0ubuntu1.1
ProcVersionSignature: Ubuntu 3.13.0-37.64-generic 3.13.11.7
Uname: Linux 3.13.0-37-generic x86_64
ApportVersion: 2.14.1-0ubuntu3.6
Architecture: amd64
Date: Sat Nov 1 19:29:13 2014
InstallationDate: Installed on 2013-08-11 (447 days ago)
InstallationMedia: Lubuntu 13.04 "Raring Ringtail" - Release amd64 (20130423.1)
PackageArchitecture: all
ProcEnviron:
 LANGUAGE=de_DE
 TERM=xterm
 PATH=(custom, no user)
 LANG=de_DE.UTF-8
 SHELL=/bin/bash
SourcePackage: gui-ufw
UpgradeStatus: Upgraded to trusty on 2014-11-01 (0 days ago)
mtime.conffile..etc.gufw.app.profiles.network.time.protocol.jhansonxi: 2014-11-01T19:27:15.335627

Revision history for this message
Kai Henningsen (kai-bugs) wrote :
Revision history for this message
Seth Arnold (seth-arnold) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures

Changed in gui-ufw (Ubuntu):
status: New → Incomplete
information type: Private Security → Public Security
Revision history for this message
costales (costales) wrote :

Hi! Changing to UDP over port 123
Thanks a lot for your feedback!

Changed in gui-ufw:
status: New → In Progress
costales (costales)
Changed in gui-ufw:
status: In Progress → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package gui-ufw - 15.04.0-0ubuntu1

---------------
gui-ufw (15.04.0-0ubuntu1) vivid; urgency=low

  * New upstream release. Upstream changelog:
    - Fix: No reload entry menu (LP: #1375468)
    - Fix: NTP rule uses CUPS port (LP: #1388422)
    - Fix: Typos (LP: #1342355, #1374998)
    - Fix: Translated "Gufw is already running" (LP: #1375010)
    - Fix: Tutorial strings in English (LP: #1375957)
    - Updated languages
 -- Devid Antonio Filoni <email address hidden> Mon, 15 Dec 2014 20:39:33 +0100

Changed in gui-ufw (Ubuntu):
status: Incomplete → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.