suche 36x36
  • Admin-Scout-small-Banner
           

    CURSOR Admin-Scout

    get the ultimate tool for Informix

    pfeil  
Latest versionsfixlist
14.10.xC10 FixList
12.10.xC16.X5 FixList
11.70.xC9.XB FixList
11.50.xC9.X2 FixList
11.10.xC3.W5 FixList
Have problems? - contact us.
Register for free anmeldung-x26
Contact form kontakt-x26

Informix - Problem description

Problem IT27502 Status: Closed

SSL SOCKET LISTENER CAN ASSERT IN SSL_SEND IF BUMP INTO
MAX_INCOMPLETE_SESSIONS

product:
INFORMIX SERVER / 5725A3900 / C10 - IDS 12.10
Problem description:
n the case of the reproduction described below, consider the
onconfig param, MAX_INCOMPLETE_CONNECTIONS
set to 128.  If, as in a DoS attack, your count of SSL
listen_authenticate threads increases enough to bump
into MAX_INCOMPLETE_CONNECTIONS, then the socssllst thread will
assert and cause engine to crash with
a comparable message in the online.log to:

    09:05:52   128 incomplete connections at this time. System
might be under attack through invalid clients on the listener
port.
    09:05:52  Assert Failed: No Exception Handler
    09:05:52  IBM Informix Dynamic Server Version 12.10.FC7W1XV
    09:05:52   Who: Session(3315, informix@, 0, (nil))
                    Thread(19, socssllst, 0, 1)
                    File: mtex.c Line: 508
    09:05:52   Results: Exception Caught. Type: MT_EX_OS,
Context: mem
    09:05:52   Action: Please notify IBM Informix Technical
Support.
    09:05:52   See Also: /opt/informix/tmp/af.3fb3950,
shmem.3fb3950.0

And a stack like

    09:05:52  Stack for thread: 19 socssllst

     base: 0x0000000046324000
      len:   69632
       pc: 0x00000000013d2727
       tos: 0x00000000448ba3b0
    state: running
       vp: 1

    (oninit) afstack
    (oninit) mt_ex_throw_sig
    (oninit) afsig_handler
    (Linux) 
    (oninit) ssl_send
    (oninit) sendsocket
    (oninit) slSQIrsp
    (oninit) pfConRes
    (oninit) ASF_Call
    (oninit) sql_listener
    (oninit) startup
Problem Summary:
****************************************************************
* USERS AFFECTED:                                              *
* Users of IDS 12.10.xC10 and older versions.                  *
****************************************************************
* PROBLEM DESCRIPTION:                                         *
* SSL socket listener can assert in ssl_send if bump into      *
* MAX_INCOMPLETE_CONNECTIONS.                                  *
****************************************************************
* RECOMMENDATION:                                              *
****************************************************************
Local Fix:
Solution
Workaround
not known / see Local fix
Timestamps
Date  - problem reported    :
Date  - problem closed      :
Date  - last modified       :
24.12.2018
07.10.2019
07.10.2019
Problem solved at the following versions (IBM BugInfos)
12.10.xC11
Problem solved according to the fixlist(s) of the following version(s)
Informix EditionsInformix Editions
Informix Editions
DocumentationDocumentation
Documentation
IBM NewsletterIBM Newsletter
IBM Newsletter
Current BugsCurrent Bugs
Current Bugs
Bug ResearchBug Research
Bug Research
Bug FixlistsBug Fixlists
Bug Fixlists
Release NotesRelease Notes
Release Notes
Machine NotesMachine Notes
Machine Notes
Release NewsRelease News
Release News
Product LifecycleProduct Lifecycle
Lifecycle
Media DownloadMedia Download
Media Download