Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 122343 - dev-python/qscintilla <= 1.5.1 insecure runpaths
Summary: dev-python/qscintilla <= 1.5.1 insecure runpaths
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Runpath Issues (show other bugs)
Hardware: AMD64 Linux
: High normal (vote)
Assignee: Qt Bug Alias
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2006-02-10 02:50 UTC by Jaime Fullaondo
Modified: 2009-05-04 22:54 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jaime Fullaondo 2006-02-10 02:50:17 UTC
During emerge qscintilla just bails out ending like this, the compilation seems pretty much flawlees:

>>> Test phase [not enabled]: dev-python/qscintilla-1.5.1

>>> Install qscintilla-1.5.1 into /var/tmp/portage/qscintilla-1.5.1/image/ category dev-python
man:
prepallstrip:
strip: x86_64-pc-linux-gnu-strip --strip-unneeded
   usr/lib64/libqscintilla.so.5.2.0
making executable: /usr/lib64/libqscintilla.so.5.2.0

QA Notice: the following files contain insecure RUNPATH's
 Please file a bug about this at http://bugs.gentoo.org/
 For more information on this issue, kindly review:
 http://bugs.gentoo.org/81745
/usr/qt/3/lib64:/var/tmp/portage/qscintilla-1.5.1/work/qscintilla-1.62-gpl-1.5.1/qt///usr/lib64 usr/lib64/libqscintilla.so.5.2.0

I checked out the site to see if anyone had this problem too, but not finding any posts or bugs about it, I did what the emerge asks for.... file for the bug! Hope this is a minor glitch which can be easily solved.


I am currently running the following system as outputted by emerge --info:

Portage 2.0.54 (default-linux/amd64/2005.1, gcc-3.4.4, glibc-2.3.5-r2,glibc-2.3.4.20040808-r1, 2.6.15-gentoo-r1 x86_64)
=================================================================
System uname: 2.6.15-gentoo-r1 x86_64 AMD Athlon(tm) 64 Processor 3400+
Gentoo Base System version 1.6.14
distcc 2.18.3 x86_64-pc-linux-gnu (protocols 1 and 2) (default port 3632) [disabled]
dev-lang/python:     2.3.5-r2, 2.4.2
sys-apps/sandbox:    1.2.12
sys-devel/autoconf:  2.13, 2.59-r6
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r1
sys-devel/binutils:  2.16.1
sys-devel/libtool:   1.5.22
virtual/os-headers:  2.6.11-r2
ACCEPT_KEYWORDS="amd64"
AUTOCLEAN="yes"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-march=k8 -O2 -pipe -fomit-frame-pointer -frename-registers"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/kde/2/share/config /usr/kde/3/share/config /usr/share/config /var/qmail/control"
CONFIG_PROTECT_MASK="/etc/gconf /etc/env.d"
CXXFLAGS="-march=k8 -O2 -pipe -fomit-frame-pointer -frename-registers"
DISTDIR="/usr/portage/distfiles"
FEATURES="autoconfig distlocks sandbox sfperms strict"
GENTOO_MIRRORS="http://gentoo.blueyonder.co.uk http://linuv.uv.es/mirror/gentoo/"
MAKEOPTS="-j2"
PKGDIR="/usr/portage/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY="/usr/local/portage"
SYNC="rsync://rsync.gentoo.org/gentoo-portage"
USE="X acl acpi alsa amd64 apm arts audiofile avi berkdb bitmap-fonts bonobo bzip2 cdb cdr crypt cups curl dbase dbus divx4linux dvd dvdr eds emacs emboss encode esd ethereal exif expat fam ffmpeg flac foomaticdb fortran ftp gd gdbm gif gimp gimpprint glut gmp gnome gphoto2 gpm gstreamer gtk gtk2 gtkhtml guile hal icq idn imagemagick imap imlib ipv6 jack java jpeg junit kde lcms libwww lzw lzw-tiff mad maildir mhash mikmod mng motif mozilla mp3 mpeg msn mysql mysqli ncurses nls oav ogg oggvorbis openal opengl oss pam pcre pda pdflib perl php png postgres python qt quicktime readline ruby samba scanner sdl slang spell ssl tcltk tcpd tetex tiff truetype truetype-fonts type1-fonts udev usb userlocales videos vorbis wxgtk1 wxwindows xine xinerama xml xml2 xmms xpm xv xvid yahoo zlib video_cards_radeon userland_GNU kernel_linux elibc_glibc"
Unset:  ASFLAGS, CTARGET, LANG, LC_ALL, LDFLAGS, LINGUAS

If u need any additional info, just let me know.
Comment 1 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-07-15 14:49:30 UTC
Python/Qt, what's the status here? It's been a while wihtout any comment, does this issue still stands or can we close this?
Comment 2 Jakub Moc (RETIRED) gentoo-dev 2007-09-08 23:13:27 UTC
(In reply to comment #1)
> Python/Qt, what's the status here? It's been a while wihtout any comment, does
> this issue still stands or can we close this?

This is no longer a security issue, portage has been fixing these on-the-fly for over a year.

Re-assigning to maintainer.
Comment 3 Arfrever Frehtes Taifersar Arahesis (RETIRED) gentoo-dev 2009-05-04 22:54:38 UTC
dev-python/qscintilla-1.5.1 is no longer in the tree.