First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 74011
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Daniel Webert <rockoo@gmail.com>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 74011 depends on: 79926 Show dependency tree
Show dependency graph
Bug 74011 blocks:

Additional Comments: (this is where you put emerge --info)







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-12-10 08:43 0000
glsa-check/automake-wrapper false alarm

<snip>
porkoo ~ # glsa-check -t all
WARNING: This ...

This system is affected by the following GLSA:
200404-08
</snip>

<snip>
GLSA 200404-08: 
GNU Automake symbolic link vulnerability          
============================================================================
Synopsis: ...

Affected package:  sys-devel/automake
Affected archs:    All
Vulnerable:        <1.8.3
Unaffected:        >=1.8.3
</snip>

<snip>
porkoo ~ # equery l -p automake
[ Searching for package 'automake' in all categories among: ]
 * installed packages
[I--] [  ] sys-devel/automake-1.4_p6 (1.4)
[I--] [  ] sys-devel/automake-1.5 (1.5)
[I--] [  ] sys-devel/automake-1.6.3 (1.6)
[I--] [  ] sys-devel/automake-1.7.9 (1.7)
[I--] [  ] sys-devel/automake-1.9.3 (1.9)
[I--] [  ] sys-devel/automake-1.8.5-r2 (1.8)
[I--] [  ] sys-devel/automake-wrapper-1 (0)
 * Portage tree (/usr/portage)
[-P-] [  ] sys-devel/automake-1.8.5-r1 (1.5)
</snip>

------- Comment #1 From Thierry Carrez (RETIRED) 2004-12-10 13:14:25 0000 -------
GLSA says all automake < 1.8.3 is vulnerable. You have automake-1.4_p6,
automake-1.5, automake-1.6.3 and automake-1.7.9 installed. glsa-check says you
are affected. Looks like glsa-check is right. Please explain how this is an
error.

------- Comment #2 From Thierry Carrez (RETIRED) 2004-12-10 13:30:20 0000 -------
After a little chat it's a little more clear...

automake-wrapper has the following RDEPENDS:
RDEPEND="=sys-devel/automake-1.4*
         =sys-devel/automake-1.5*
         =sys-devel/automake-1.6*
         =sys-devel/automake-1.7*
         =sys-devel/automake-1.8.5-r2
         =sys-devel/automake-1.9*"

[M~] sys-devel/automake-1.5 (1.5)
[M~] sys-devel/automake-1.4_p6 (1.4)
[M~] sys-devel/automake-1.6.3 (1.6)
[M~] sys-devel/automake-1.7.9 (1.7)
[  ] sys-devel/automake-1.8.5-r1 (1.5)
[M~] sys-devel/automake-1.8.5-r2 (1.8)
[M~] sys-devel/automake-1.9.3 (1.9)

So portage still contains (probably) vulnerable versions... And automake-wrapper even requires them.

base-system, please advise... Are all these versions fixed ? Will they be ? If not, can they be removed ?

------- Comment #3 From SpanKY 2004-12-10 13:46:21 0000 -------
can/will they be removed ? no, probably never

those versions have always been in the tree ... 1.8.5-r1 and earlier always packaged the older versions in one ebuild

are they fixed ?  i have nfc what the bug is so i couldnt tell you

------- Comment #4 From Thierry Carrez (RETIRED) 2004-12-10 14:30:26 0000 -------
clue: GLSA 200404-08, bug 45646
Looks like a tempfile vuln, was fixed by solar through :

-	epatch ${FILESDIR}/${P}-infopage-namechange.patch
+	epatch ${FILESDIR}/${PN}-1.8.2-infopage-namechange.patch

I suppose the other versions (other than the stable 1.8.* slot) are not fixed.

------- Comment #5 From SpanKY 2004-12-10 18:08:25 0000 -------
the vuln seems to have been introduced during the 1.7.x cycle

that means 1.4_p6, 1.5, and 1.6.3 are not affected

ive added the patch to 1.7.9, 1.8.5-r2, and made a new patch for 1.9.3 ... i thought this was supposed to be fixed upstream ?

------- Comment #6 From Thierry Carrez (RETIRED) 2004-12-14 07:11:13 0000 -------
Hmm it was before my time, so I don't know if it was forwarded upstream.
Obviously it wasn't, or upstream didn't care.

Could you revbump to 1.7.9-r1 and 1.9.3-r1 so that we can update the old GLSA
instructions to match ?

About 1.8.5-r2, didn't it already have the patch ? If not, then revbump to -r3
too (and remove once-affected -r2 to simplify)

------- Comment #7 From SpanKY 2004-12-23 22:41:33 0000 -------
*** Bug 75477 has been marked as a duplicate of this bug. ***

------- Comment #8 From Robert Muchacki (RETIRED) 2004-12-27 23:18:19 0000 -------
The problem still exists...

------- Comment #9 From Chris Slycord 2005-01-27 15:46:29 0000 -------
This bug has been here for months... any idea when it might get fixed?

------- Comment #10 From DC 2005-01-27 15:50:39 0000 -------
Hi, I'm just did an emerge sync, and I'm noticing that Portage suddenly wants
to install half a dozen versions of automake (and a few of autoconf). Can
someone on this thread tell me why automake-wrapper tries to install so many
versions of automake, and why we suddenly need them all now, when we didn't
need them before?

------- Comment #11 From Thierry Carrez (RETIRED) 2005-01-28 02:19:05 0000 -------
Chris: this bug hasn't been sitting there for months, but just for a month.
It's partially fixed (portage does not carry any vulnerable version anymore)
but still needs a few revbumps and an updated GLSA so that glsa-check does not
report you're vulnerable while you're not.

vapier: currently portage has :
sys-devel/automake-1.4_p6 (1.4) -> not affected
sys-devel/automake-1.5 (1.5) -> not affected
sys-devel/automake-1.6.3 (1.6) -> not affected
sys-devel/automake-1.7.9 (1.7) -> patched, requires revbump
sys-devel/automake-1.8.5-r2 (1.8) -> patched, requires revbump ?
sys-devel/automake-1.9.4 (1.9) -> patched (SLOT always included the patch)

Please revbump those who need it, and tell me which 1.8.5 version includes the
fix, so that we can update GLSA 200404-08 as :

Unaffected :
sys-devel/automake <  1.7
sys-devel/automake *>= 1.7.9-r1
sys-devel/automake >= 1.8.5-r3 (or is it 1.8.5 ?)

Affected :
sys-devel/automake < 1.8.5-r3 (or is it 1.8.5 ?)

------- Comment #12 From Chris Slycord 2005-01-28 12:22:00 0000 -------
How does one revbump?  I'm confused.

And there is no automake-1.8.5-r3 at least not in portage.  r2 is the highest I see.

------- Comment #13 From Thierry Carrez (RETIRED) 2005-01-28 14:16:26 0000 -------
All what is below "vapier:" in my latest comment is for vapier (the package
maintainer) not for you. He is the one that will do the revbumping (i.e. create
new ebuild revisions).

------- Comment #14 From SpanKY 2005-01-28 23:12:48 0000 -------
sys-devel/automake-1.7.9-r1 and sys-devel/automake-1.8.5-r3 have both been rev
bumped

------- Comment #15 From Thierry Carrez (RETIRED) 2005-01-29 01:12:03 0000 -------
alpha, sparc, mips, ppc, ppc64:
Do you plan on using the new SLOTed automake(s) anytime soon ? I have to update the GLSA for the arches who do (amd64,arm,hppa,ia64,s390,sh,x86), but it may be simpler to wait for you to use them too, if it's soon.

To make the switch you have to mark stable :
sys-devel/automake-1.4_p6 (1.4)
sys-devel/automake-1.5 (1.5)
sys-devel/automake-1.6.3 (1.6)
sys-devel/automake-1.7.9-r1 (1.7)
sys-devel/automake-1.8.5-r3 (1.8)
sys-devel/automake-1.9.4 (1.9)

If you can't do it for whatever reason, please comment so that I don't wait for you to fix the GLSA.

------- Comment #16 From Lourdes Jones 2005-01-29 01:47:06 0000 -------
Well, sys-devel/automake-1.8.5-r3 is in portage today, but
sys-devel/automake-1.8.5-r2 is now masked and since automake-wrapper still
specifies sys-devel/automake-1.8.5-r2 in it's dependencies now "emerge -uD
anything" or "emerge -e anything" no longer work.

Can we please have an updated autmake-wrapper that has a sensible depends like
"=sys-devel/automake-1.8*" and avoid this problem?

------- Comment #17 From Thierry Carrez (RETIRED) 2005-01-29 01:59:48 0000 -------
vapier: automake-wrapper needs a quick fix to handle the new rev...

------- Comment #18 From Kalin KOZHUHAROV 2005-01-29 02:20:43 0000 -------
Yes it does, see the pile-up on bug #79926
May be mark this bug as blocker for #79926 ?

------- Comment #19 From Markus Rothe 2005-01-29 14:10:29 0000 -------
stable on ppc64

------- Comment #20 From Chris Slycord 2005-01-29 14:19:30 0000 -------
I can confirm that automake-1.8.5-r3 was installed on my box but glsa-check
still removes automake-1.5 (and installs automake-1.8.5-r1 in it's place).

So, I'm assuming this means that the glsa-check script will simply be changed
sometime in the future for this.

------- Comment #21 From SpanKY 2005-01-29 20:38:43 0000 -------
err, sorry, fixed automake-wrapper

we cant depend on 1.8* yet because 1.8.5-r1 will match that

------- Comment #22 From Michael Hanselmann (hansmi) (RETIRED) 2005-01-30 03:35:20 0000 -------
Stable on ppc.

------- Comment #23 From Bryan Østergaard (RETIRED) 2005-01-30 14:12:42 0000 -------
Alpha keyworded.

------- Comment #24 From Thierry Carrez (RETIRED) 2005-01-31 05:09:42 0000 -------
Still needing sparc to mark stable as detailed in comment #15.
Then we'll proceed in updating the GLSA as detailed in comment #11.

------- Comment #25 From Gustavo Zacarias (RETIRED) 2005-01-31 07:23:20 0000 -------
sparc done.

------- Comment #26 From Thierry Carrez (RETIRED) 2005-01-31 09:11:29 0000 -------
new GLSA 200404-08 committed to Portage. Should be on mirrors in 30 minutes,
please test that it accurately reports vulnerability status.

------- Comment #27 From Mark 2005-01-31 15:14:46 0000 -------
glsa-check -f 200404-08
This re-emerged 1.8.5-r3

So it was still complaining.. I needed to:
emerge =automake-1.7.9-r1

then the glsa-check showed clear....
Cheers all..

------- Comment #28 From Thierry Carrez (RETIRED) 2005-02-04 02:14:30 0000 -------
I'll suppose this means it works... Please reopen if it doesn't.

------- Comment #29 From Hardave Riar (RETIRED) 2005-02-19 14:59:23 0000 -------
Mips done.

First Last Prev Next    No search results available      Search page      Enter new bug