First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 105717
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Ashu Tiwary <ashutiwary@gmail.com>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
3135-imagemagick-6.2.4.2.log logfile for "emerge -v media-gfx/imagemagick" text/plain Ashu Tiwary 2005-09-12 12:11 0000 272.25 KB Details
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 105717 depends on: Show dependency tree
Bug 105717 blocks: 81745

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-09-12 12:10 0000
when emerging media-gfx/imagemagick-6.2.4.2, the emerge fails w/ "insecure
RUNPATH's":

   usr/lib/ImageMagick-6.2.4/modules-Q16/filters/analyze.so
   usr/lib/libMagick++.so.6.2.4
   usr/lib/libMagick.so.6.2.4
   usr/lib/libWand.so.6.2.4
   usr/lib/perl5/vendor_perl/5.8.7/i686-linux/auto/Image/Magick/Magick.so
making executable: /usr/lib/libMagick++.so.6.2.4
making executable: /usr/lib/libMagick.so.6.2.4
making executable: /usr/lib/libWand.so.6.2.4
^G
QA Notice: the following files contain insecure RUNPATH's
 Please file a bug about this at http://bugs.gentoo.org/
 For more information on this issue, kindly review:
 http://bugs.gentoo.org/81745
/portage/tmp/portage/imagemagick-6.2.4.2/work/ImageMagick-6.2.4/PerlMagick/../magick/.libs:/usr/lib
usr/lib/perl5/vendor
_perl/5.8.7/i686-linux/auto/Image/Magick/Magick.so
^G

!!! ERROR: media-gfx/imagemagick-6.2.4.2 failed.
!!! Function dyn_install, Line 1044, Exitcode 0
!!! Insecure binaries detected
!!! If you need support, post the topmost build error, NOT this status message.



Reproducible: Always
Steps to Reproduce:
1. emerge media-gfx/imagemagick
2.
3.

Actual Results:  
see above

Expected Results:  
should successfully emerge

liberte insecure_runpaths # emerge --info
Portage 2.0.52-r1 (default-linux/x86/2005.1, gcc-3.4.4, glibc-2.3.5-r1,
2.6.13-gentoo i686)
=================================================================
System uname: 2.6.13-gentoo i686 Intel(R) Pentium(R) M processor 1700MHz
Gentoo Base System version 1.12.0_pre8
dev-lang/python:     2.3.5, 2.4.1-r1
sys-apps/sandbox:    1.2.12
sys-devel/autoconf:  2.13, 2.59-r7
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6
sys-devel/binutils:  2.16.1
sys-devel/libtool:   1.5.20
virtual/os-headers:  2.6.11-r2
ACCEPT_KEYWORDS="x86 ~x86"
AUTOCLEAN="yes"
CBUILD="i686-pc-linux-gnu"
CFLAGS="-O3 -pipe -march=pentium-m -mtune=pentium-m -fweb -ftracer"
CHOST="i686-pc-linux-gnu"
CONFIG_PROTECT="/etc /opt/openjms/config /usr/kde/2/share/config
/usr/kde/3.4/env /usr/kde/3.4/share/config /usr/kde/3.4/shutdown
/usr/kde/3/share/config /usr/lib/X11/xkb /usr/lib/mozilla/defaults/pref
/usr/share/config /var/qmail/control"
CONFIG_PROTECT_MASK="/etc/gconf /etc/terminfo /etc/texmf/web2c /etc/env.d"
CXXFLAGS="-O3 -pipe -march=pentium-m -mtune=pentium-m -fweb -ftracer"
DISTDIR="/portage/distfiles"
FEATURES="autoconfig distlocks fixpackages sandbox sfperms strict userpriv"
GENTOO_MIRRORS="http://gentoo.osuosl.org/
ftp://distro.ibiblio.org/pub/linux/distributions/gentoo/
ftp://ftp.gtlib.cc.gatech.edu/pub/gentoo http://mirror.datapipe.net/gentoo
ftp://mirror.mcs.anl.gov/pub/gentoo/"
LINGUAS="en ar bg bn br bs ca cs cy da de el en_GB eo es et eu fi fr fy ga he hi
hsb hu is it ja lt mk nb nds nl nn pa pl pt pt_BR ro ru se sk sl sr sr@Latn sv
ta tg tr uk zh_CN zh_TW"
PKGDIR="/portage/packages"
PORTAGE_TMPDIR="/portage/tmp"
PORTDIR="/usr/portage"
SYNC="rsync://rsync.gentoo.org/gentoo-portage"
USE="x86 X aalib alsa apm arts avi bash-completion berkdb bitmap-fonts cdr crypt
cscope cups curl directfb doc eds emboss encode erandom esd fam flac foomaticdb
fortran freetds g++ g77 gcj gd gdbm ggi gif gjava gnat gnome gobjc gpm gstreamer
gtk gtk2 guile imagemagick imlib ipv6 jack java jpeg junit kde ldap libg++
libwww lirc mad mcal mikmod motif mozilla mp3 mpeg mysql nas ncurses nls nptl
nptlonly objc odbc ogg oggvorbis opengl oss pam pdflib perl pic png postgres
python qt quicktime readline ruby samba sdl slang snmp speex spell sqlite ssl
svga tcltk tcpd tetex tiff truetype truetype-fonts type1-fonts unicode
userlocales vorbis xml xml2 xmms xv zlib linguas_en linguas_ar linguas_bg
linguas_bn linguas_br linguas_bs linguas_ca linguas_cs linguas_cy linguas_da
linguas_de linguas_el linguas_en_GB linguas_eo linguas_es linguas_et linguas_eu
linguas_fi linguas_fr linguas_fy linguas_ga linguas_he linguas_hi linguas_hsb
linguas_hu linguas_is linguas_it linguas_ja linguas_lt linguas_mk linguas_nb
linguas_nds linguas_nl linguas_nn linguas_pa linguas_pl linguas_pt linguas_pt_BR
linguas_ro linguas_ru linguas_se linguas_sk linguas_sl linguas_sr
linguas_sr@Latn linguas_sv linguas_ta linguas_tg linguas_tr linguas_uk
linguas_zh_CN linguas_zh_TW userland_GNU kernel_linux elibc_glibc"
Unset:  ASFLAGS, CTARGET, LANG, LC_ALL, LDFLAGS, MAKEOPTS, PORTDIR_OVERLAY

liberte insecure_runpaths # grep media-gfx/imagemagick /etc/portage/package.use
media-gfx/imagemagick X cups doc fpx graphviz jbig jpeg lcms mpeg perl png tiff
truetype wmf xml2

------- Comment #1 From Ashu Tiwary 2005-09-12 12:11:24 0000 -------
Created an attachment (id=68278) [details]
logfile for "emerge -v media-gfx/imagemagick"

------- Comment #2 From Ashu Tiwary 2005-09-12 12:12:46 0000 -------
i was able to successfully emerge imagemagick using the makemaker perl hack
described in bug id 105054

------- Comment #3 From Thierry Carrez (RETIRED) 2005-09-14 03:06:24 0000 -------
This should be automatically fixed when the MakeMaker patch from bug 105054 is
committed, just requiring a bump to propagate.

------- Comment #4 From Thierry Carrez (RETIRED) 2005-09-21 05:34:41 0000 -------
Reporter : could you please check that it still happens after the latest Perl
upgrade...

------- Comment #5 From Ashu Tiwary 2005-09-22 02:46:08 0000 -------
this emerge works fine now after the last perl update (perl-5.8.7-r1)

------- Comment #6 From Thierry Carrez (RETIRED) 2005-09-23 13:36:31 0000 -------
Common GLSA with other RUNPATH issues

------- Comment #7 From Thierry Carrez (RETIRED) 2005-10-10 01:10:04 0000 -------
graphics team: we'll need a revbumps with the new Perl DEPEND so that currently
affected users get their version as "vulnerable"...

------- Comment #8 From Thierry Carrez (RETIRED) 2005-10-12 02:26:54 0000 -------
graphics herd, please do the revbumps so that we can issue the GLSA about this.

------- Comment #9 From Thierry Carrez (RETIRED) 2005-10-13 07:45:06 0000 -------
The revbump must have the following Perl dep :
    >=dev-lang/perl-5.8.6-r6
    !=dev-lang/perl-5.8.7

------- Comment #10 From Thierry Carrez (RETIRED) 2005-10-18 06:18:43 0000 -------
sekretarz should have a look at it later today

------- Comment #11 From Karol Wojtaszek (RETIRED) 2005-10-19 16:11:36 0000 -------
Version bumped in portage

------- Comment #12 From Thierry Carrez (RETIRED) 2005-10-20 02:39:14 0000 -------
Is this specific to >=6.2.4.2 ? If yes this bug can be closed (only ~ versions
affected). If not we should have a revbump on 6.2.2.3-r1 too...

------- Comment #13 From Thierry Carrez (RETIRED) 2005-10-27 02:48:33 0000 -------
Probably better to mark >=6.2.4.2-r1 stable...

Arch testers please mark 6.2.4.2-r1 (or 6.2.5.2 if you feel adventurous) stable
Target KEYWORDS="alpha amd64 arm hppa ia64 mips ppc ppc64 sparc x86"

------- Comment #14 From Gustavo Zacarias (RETIRED) 2005-10-27 07:15:43 0000 -------
sparc stable.

------- Comment #15 From Andrej Kacian (RETIRED) 2005-10-27 07:31:34 0000 -------
x86 happy

------- Comment #16 From Brent Baude 2005-10-27 08:15:43 0000 -------
ppc64 stable

------- Comment #17 From Simon Stelling (RETIRED) 2005-10-27 12:50:15 0000 -------
6.2.4.2-r1 stable on amd64

------- Comment #18 From Jose Luis Rivero (yoswink) 2005-10-27 15:32:23 0000 -------
6.2.4.2-r1 stable on alpha

------- Comment #19 From Michael Hanselmann (hansmi) (RETIRED) 2005-10-29 08:47:01 0000 -------
Stable on ppc and hppa.

------- Comment #20 From Bryan Østergaard (RETIRED) 2005-10-29 13:03:53 0000 -------
Stable on ia64.

------- Comment #21 From Thierry Carrez (RETIRED) 2005-10-30 07:01:00 0000 -------
Ready for GLSA

------- Comment #22 From Thierry Carrez (RETIRED) 2005-10-30 07:19:46 0000 -------
Common GLSA with GDAL and qdbm

------- Comment #23 From Thierry Carrez (RETIRED) 2005-11-01 05:10:12 0000 -------
GLSA Batch ready.

------- Comment #24 From Thierry Carrez (RETIRED) 2005-11-02 09:19:23 0000 -------
GLSA 200511-02
mips should mark stable to benefit from GLSA

First Last Prev Next    No search results available      Search page      Enter new bug