Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 187994
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Web Application Packages Maintainers <web-apps@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Tobias Klausmann <klausman@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff-3286.out awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff patch log text/plain Tobias Klausmann 2007-08-07 12:16 0000 17.72 KB Details
awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff Fixed awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff patch Alexander Skwar 2007-08-08 07:19 0000 5.75 KB Details | Diff
awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff Yet another awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff patch Thomas S. Howard 2007-09-01 20:21 0000 4.89 KB Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 187994 depends on: Show dependency tree
Bug 187994 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-08-07 12:15 0000
>>> Emerging (1 of 1) net-www/awstats-6.5-r2 to /
 * awstats-6.5.tar.gz RMD160 ;-) ...                                      [ ok
]
 * awstats-6.5.tar.gz SHA1 ;-) ...                                        [ ok
]
 * awstats-6.5.tar.gz SHA256 ;-) ...                                      [ ok
]
 * awstats-6.5.tar.gz size ;-) ...                                        [ ok
]
 * checking ebuild checksums ;-) ...                                      [ ok
]
 * checking auxfile checksums ;-) ...                                     [ ok
]
 * checking miscfile checksums ;-) ...                                    [ ok
]
 * checking awstats-6.5.tar.gz ;-) ...                                    [ ok
]
>>> Unpacking source...
>>> Unpacking awstats-6.5.tar.gz to /var/tmp/portage/net-www/awstats-6.5-r2/work
 * Applying awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff ...

 * Failed Patch: awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff !
 *  (
/usr/portage/net-www/awstats/files/awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff
)
 * 
 * Include in your bugreport the contents of:
 * 
 *  
/var/tmp/portage/net-www/awstats-6.5-r2/temp/awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff-3286.out

 * 
 * ERROR: net-www/awstats-6.5-r2 failed.
 * Call stack:
 *   ebuild.sh, line 1648:   Called dyn_unpack
 *   ebuild.sh, line 768:   Called qa_call 'src_unpack'
 *   ebuild.sh, line 44:   Called src_unpack
 *   awstats-6.5-r2.ebuild, line 33:   Called epatch
'/usr/portage/net-www/awstats/files/awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff'
 *   eutils.eclass, line 304:   Called die
 * 
 * Failed Patch: awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff!
 * If you need support, post the topmost build error, and the call stack if
relevant.
 * A complete build log is located at
'/var/log/portage/net-www:awstats-6.5-r2:20070807-115836.log'.
 * 

# emerge --info
Portage 2.1.3.3 (default-linux/x86/2006.1/desktop, gcc-4.2.0, glibc-2.6-r0,
2.6.22.1 i686)
=================================================================
System uname: 2.6.22.1 i686 AMD Athlon(tm) XP 2500+
Gentoo Base System release 1.12.10
Timestamp of tree: Tue, 07 Aug 2007 00:50:01 +0000
dev-java/java-config: 1.3.7, 2.0.33-r1
dev-lang/python:     2.4.4-r4
dev-python/pycrypto: 2.0.1-r6
sys-apps/sandbox:    1.2.18.1
sys-devel/autoconf:  2.13, 2.61-r1
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2, 1.10
sys-devel/binutils:  2.17-r1
sys-devel/gcc-config: 1.3.16
sys-devel/libtool:   1.5.24
virtual/os-headers:  2.6.22-r2
ACCEPT_KEYWORDS="x86 ~x86"
AUTOCLEAN="yes"
CBUILD="i686-pc-linux-gnu"
CFLAGS="-march=athlon-xp -O2 -pipe -fomit-frame-pointer"
CHOST="i686-pc-linux-gnu"
CONFIG_PROTECT="/etc /opt/openfire/resources/security/"
CONFIG_PROTECT_MASK="/etc/env.d /etc/env.d/java/ /etc/gconf
/etc/php/apache2-php5/ext-active/ /etc/php/cgi-php5/ext-active/
/etc/php/cli-php5/ext-active/ /etc/revdep-rebuild /etc/terminfo"
CXXFLAGS="-march=athlon-xp -O2 -pipe -fomit-frame-pointer"
DISTDIR="/usr/portage/distfiles"
FEATURES="distlocks metadata-transfer parallel-fetch sandbox sfperms strict
unmerge-orphans userfetch userpriv usersandbox"
GENTOO_MIRRORS="http://pandemonium.tiscali.de/pub/gentoo/
http://mirrors.sec.informatik.tu-darmstadt.de/gentoo/
http://gentoo.mirror.solnet.ch"
LC_ALL="en_US.utf8"
MAKEOPTS="-j2"
PKGDIR="/usr/portage/packages"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress
--force --whole-file --delete --delete-after --stats --timeout=180
--exclude=/distfiles --exclude=/local --exclude=/packages
--filter=H_**/files/digest-*"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY="/usr/local/portage"
SYNC="rsync://rsync5.de.gentoo.org/gentoo-portage"
USE="3dnow acl acpi alsa apache2 apm bash-completion bcmath berkdb bitmap-fonts
bzip2 cairo caps cdr claendar clamav cli cracklib crypt cscope cups curl dbus
dio dri dvd dvdr emboss encode ethereal exif fam firefox fortran ftp gd gdbm
gif gmp gnutls gpm gstreamer gtk2 hal iconv idn imagemagick imap imlib isdnlog
jabber jpeg kdeenablefinal libg++ libwww mad maildir mbox midi mikmod mmap mmx
mng mp3 mpeg mpi mudflap mysql mysqli ncurses nls nptl nptlonly offensive ogg
oggvorbis openmp oss pam pcre perl php png posix ppds pppd python qt3 qt4
quicktime readline recide reflection sasl session sockets spell spl sse ssl svg
tcpd truetype truetype-fonts type1-fonts unicode vhosts vorbis win32codecs x86
xml xorg xv zlib" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106
cmipci emu10k1 emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0
intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci"
ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file
hooks iec958 ioplug ladspa lfloat linear meter mulaw multi null plug rate route
share shm softvol" ELIBC="glibc" INPUT_DEVICES="keyboard mouse" KERNEL="linux"
LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses
text" USERLAND="GNU" VIDEO_CARDS="vesa vga v4l"
Unset:  CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LANG, LDFLAGS, LINGUAS,
PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS

I'll also attach the patch log.

------- Comment #1 From Tobias Klausmann 2007-08-07 12:16:31 0000 -------
Created an attachment (id=127161) [details]
awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff patch log

------- Comment #2 From Jakub Moc (RETIRED) 2007-08-07 12:48:20 0000 -------
Wonderful. As noted on Bug 185151, upstream should damn stop messing with
released tarballs!

------- Comment #3 From Jakub Moc (RETIRED) 2007-08-08 07:13:58 0000 -------
*** Bug 188073 has been marked as a duplicate of this bug. ***

------- Comment #4 From Alexander Skwar 2007-08-08 07:19:21 0000 -------
Created an attachment (id=127248) [details]
Fixed awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff

This is a fixed version of the patch. 

Patching failed on logresolvemerge.pl. It seems, as if this file now has dos
fileendings. The attached patch now also dos endings for the logresolvemerge.pl
file.

------- Comment #5 From Michael Härtl 2007-08-09 08:11:01 0000 -------
This also happens for awstats-6.5-r1 like mentioned in #185151 which is now
"FIXED". This is really a mess, since i've installed exactly the same version
on a machine some month earlier. I second Jacub Moc: IMHO changing a released
package is quite brainless...

[iwan etc]# emerge awstats
Calculating dependencies... done!
>>> Verifying ebuild Manifests...

>>> Emerging (1 of 1) net-www/awstats-6.5-r1 to /
 * awstats-6.5.tar.gz RMD160 ;-) ...                                           
                                       [ ok ]
 * awstats-6.5.tar.gz SHA1 ;-) ...                                             
                                       [ ok ]
 * awstats-6.5.tar.gz SHA256 ;-) ...                                           
                                       [ ok ]
 * awstats-6.5.tar.gz size ;-) ...                                             
                                       [ ok ]
 * checking ebuild checksums ;-) ...                                           
                                       [ ok ]
 * checking auxfile checksums ;-) ...                                          
                                       [ ok ]
 * checking miscfile checksums ;-) ...                                         
                                       [ ok ]
 * checking awstats-6.5.tar.gz ;-) ...                                         
                                       [ ok ]
>>> Unpacking source...
>>> Unpacking awstats-6.5.tar.gz to /var/tmp/portage/net-www/awstats-6.5-r1/work
 * Applying awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff ...

 * Failed Patch: awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff !
 *  (
/usr/portage/net-www/awstats/files/awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff
)
 *
 * Include in your bugreport the contents of:
 *
 *  
/var/tmp/portage/net-www/awstats-6.5-r1/temp/awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff-8707.out


!!! ERROR: net-www/awstats-6.5-r1 failed.
Call stack:
  ebuild.sh, line 1632:   Called dyn_unpack
  ebuild.sh, line 763:   Called qa_call 'src_unpack'
  ebuild.sh, line 44:   Called src_unpack
  awstats-6.5-r1.ebuild, line 32:   Called epatch
'/usr/portage/net-www/awstats/files/awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff'
  eutils.eclass, line 304:   Called die

!!! Failed Patch: awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff!
!!! If you need support, post the topmost build error, and the call stack if
relevant.
!!! A complete build log is located at
'/var/tmp/portage/net-www/awstats-6.5-r1/temp/build.log'.

------- Comment #6 From Jakub Moc (RETIRED) 2007-08-19 15:51:11 0000 -------
*** Bug 189485 has been marked as a duplicate of this bug. ***

------- Comment #7 From Steven Elling 2007-08-19 17:10:59 0000 -------
The same patch distributed with the portage tree fails for me as well.

The new patch included with this bug report works for me.

Linux 2.6.22-gentoo-r2 #1 SMP PREEMPT Sun Aug 5 16:40:29 CDT 2007 x86_64
Intel(R) Core(TM)2 Duo CPU T7300 @ 2.00GHz GenuineIntel GNU/Linux

------- Comment #8 From Kevin Zuber 2007-08-20 17:26:54 0000 -------
Same Problem with original ebuild-patch her.

------- Comment #9 From Martin Büdenbender 2007-08-20 18:19:29 0000 -------
patch worked for me ... thanks

------- Comment #10 From jcat 2007-09-01 16:56:16 0000 -------
I'm seeing something similar, and the patch doesn't fix it.


 * Applying awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff ...

 * Failed Patch: awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff !
 *  (
/usr/portage/net-www/awstats/files/awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff
)
 * 
 * Include in your bugreport the contents of:
 * 
 *  
/var/tmp/portage/net-www/awstats-6.5-r1/temp/awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff-15867.out

 * 
 * ERROR: net-www/awstats-6.5-r1 failed.
 * Call stack:
 *   ebuild.sh, line 1654:   Called dyn_unpack
 *   ebuild.sh, line 768:   Called qa_call 'src_unpack'
 *   ebuild.sh, line 44:   Called src_unpack
 *   awstats-6.5-r1.ebuild, line 32:   Called epatch
'/usr/portage/net-www/awstats/files/awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff'
 *   eutils.eclass, line 304:   Called die
 * 
 * Failed Patch: awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff!
 * If you need support, post the topmost build error, and the call stack if
relevant.
 * A complete build log is located at
'/var/log/portage/net-www:awstats-6.5-r1:20070901-165201.log'.
 * 


Any ideas?  Is this related?


Cheers,
jcat

------- Comment #11 From Thomas S. Howard 2007-09-01 20:21:52 0000 -------
Created an attachment (id=129804) [details]
Yet another awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff

(In reply to comment #10)

> Any ideas?  Is this related?
> 

OK, I toyed around with it, and in this case, recreating the patch from scratch
(again) and leaving out the DOS junk got it to apply.  So, I guess if it breaks
try the first patch by Alexander, then if that doesn't work, try mine.

------- Comment #12 From jcat 2007-09-02 01:31:59 0000 -------
Thanks for the quick response! :)

Unfortunately I still seem to get the error:


# emerge -av awstats

These are the packages that would be merged, in order:

Calculating dependencies... done!
[ebuild  N    ] net-www/awstats-6.5-r1  USE="-vhosts" 0 kB 

Total: 1 package (1 new), Size of downloads: 0 kB

Would you like to merge these packages? [Yes/No] yes
>>> Verifying ebuild Manifests...

>>> Emerging (1 of 1) net-www/awstats-6.5-r1 to /
 * awstats-6.5.tar.gz MD5 ;-) ...                                              
                                                   [ ok ]
 * awstats-6.5.tar.gz RMD160 ;-) ...                                           
                                                   [ ok ]
 * awstats-6.5.tar.gz SHA1 ;-) ...                                             
                                                   [ ok ]
 * awstats-6.5.tar.gz SHA256 ;-) ...                                           
                                                   [ ok ]
 * awstats-6.5.tar.gz size ;-) ...                                             
                                                   [ ok ]
 * checking ebuild checksums ;-) ...                                           
                                                   [ ok ]
 * checking auxfile checksums ;-) ...                                          
                                                   [ ok ]
 * checking miscfile checksums ;-) ...                                         
                                                   [ ok ]
 * checking awstats-6.5.tar.gz ;-) ...                                         
                                                   [ ok ]
>>> Unpacking source...
>>> Unpacking awstats-6.5.tar.gz to /var/tmp/portage/net-www/awstats-6.5-r1/work
 * Applying awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff ...

 * Failed Patch: awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff !
 *  (
/usr/portage/net-www/awstats/files/awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff
)
 * 
 * Include in your bugreport the contents of:
 * 
 *  
/var/tmp/portage/net-www/awstats-6.5-r1/temp/awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff-28641.out

 * 
 * ERROR: net-www/awstats-6.5-r1 failed.
 * Call stack:
 *   ebuild.sh, line 1654:   Called dyn_unpack
 *   ebuild.sh, line 768:   Called qa_call 'src_unpack'
 *   ebuild.sh, line 44:   Called src_unpack
 *   awstats-6.5-r1.ebuild, line 32:   Called epatch
'/usr/portage/net-www/awstats/files/awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff'
 *   eutils.eclass, line 304:   Called die
 * 
 * Failed Patch: awstats-6.5-CVE-2006-2237-CVE-2006-1945.diff!
 * If you need support, post the topmost build error, and the call stack if
relevant.
 * A complete build log is located at
'/var/log/portage/net-www:awstats-6.5-r1:20070902-012933.log'.
 * 


Perhaps this is a different issue?  What do you think?


Cheers,
jcat

------- Comment #13 From Benedikt Böhm 2007-09-06 18:47:40 0000 -------
i rediffed the cve patch, fixes both 6.5-r1 and 6.5-r2 in place

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug