Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 124106 - gaim-2.0.0_beta2-r1 insecure runpath
Summary: gaim-2.0.0_beta2-r1 insecure runpath
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Runpath Issues (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2006-02-25 14:23 UTC by Alan Strohm
Modified: 2006-05-07 06:47 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alan Strohm 2006-02-25 14:23:05 UTC
removing executable bit: /usr/lib64/libgaim-client.la
scanelf: rpath_security_checks(): Security problem NULL DT_RPATH in /var/tmp/portage/gaim-2.0.0_beta2-r1/image//usr/lib64/perl5/vendor_perl/5.8.8/x86_64-linux/auto/Gaim/Gaim.so
scanelf: rpath_security_checks(): Security problem NULL DT_RUNPATH in /var/tmp/portage/gaim-2.0.0_beta2-r1/image//usr/lib64/perl5/vendor_perl/5.8.8/x86_64-linux/auto/Gaim/Gaim.so

% emerge --info
Portage 2.1_pre4-r1 (default-linux/amd64/2005.0, gcc-3.4.2, glibc-2.3.6-r2, 2.6.15-gentoo-r1 x86_64)
=================================================================
System uname: 2.6.15-gentoo-r1 x86_64 AMD Athlon(tm) 64 Processor 3000+
Gentoo Base System version 1.12.0_pre16
distcc 2.18.3 x86_64-pc-linux-gnu (protocols 1 and 2) (default port 3632) [disabled]
ccache version 2.3 [enabled]
dev-lang/python:     2.3.5, 2.4.2-r1
sys-apps/sandbox:    1.2.17
sys-devel/autoconf:  2.13, 2.59-r7
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r1
sys-devel/binutils:  2.15.90.0.1.1-r3, 2.15.92.0.2-r1, 2.15.92.0.2-r8, 2.16-r1, 2.16.1-r1
sys-devel/libtool:   1.5.22
virtual/os-headers:  2.6.11-r3
ACCEPT_KEYWORDS="amd64 ~amd64"
AUTOCLEAN="yes"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-fPIC -march=athlon64 -O2 -pipe"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/kde/2/share/config /usr/kde/3.2/share/config /usr/kde/3.3/env /usr/kde/3.3/share/config /usr/kde/3.3/shutdown /usr/kde/3.4/env /usr/kde/3.4/share/config /usr/kde/3.4/shutdown /usr/kde/3.5/env /usr/kde/3.5/share/config /usr/kde/3.5/shutdown /usr/kde/3/share/config /usr/lib/X11/xkb /usr/lib64/mozilla/defaults/pref /usr/share/config /var/qmail/control"
CONFIG_PROTECT_MASK="/etc/gconf /etc/splash /etc/terminfo /etc/texmf/web2c /etc/env.d"
CXXFLAGS="-fPIC -march=athlon64 -O2 -pipe"
DISTDIR="/usr/portage/distfiles"
FEATURES="autoaddcvs autoconfig ccache distlocks sfperms strict"
GENTOO_MIRRORS="ftp://gentoo.mirrors.pair.com/  http://mirrors.tds.net/gentoo ftp://mirrors.tds.net/gentoo"
LANG="en_US.utf8"
LC_ALL="en_US.utf8"
MAKEOPTS="-j2"
PKGDIR="/usr/portage/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY="/usr/local/portage"
SYNC="rsync://rsync.namerica.gentoo.org/gentoo-portage"
USE="amd64 16bit 3ds X X509 Xaw3d a52 aac aim alsa amd ao apache2 arts artswrappersuid avi bash-completion beepmp berkdb bigger-fonts bitmap-fonts bluetooth bzlib cairo cddb cdparanoia cdr cgi chroot cjk codecs crypt css cups dbus dillo divx4linux doc dvd dvdr dvdread dvi eds emacs emboss encode esd evo examples fbcon ffmpeg flac foomaticdb fortran freetype gb gif gimpprint gmail gnome gpm gstreamer gtk gtk2 hal id3 idea imagemagick imap imlib ipv6 jack jack-tmpfs java javascript jpeg kde lame lzw lzw-tiff madwifi maildir mbox mozcalendar mozilla mp3 mpeg mpeg2 mpeg4 mplayer multislot musicbrainz mythtv nautilus ncurses nfsv4 nls nptl nvidia offensive ogg oggvorbis opengl pam parse-clocks pdflib perl php png ppds python qt quicktime readline real rtc samba sdl slang spell ssl startup-notification tcltk tcpd tetex tiff truetype truetype-fonts type1-fonts unicode usb userlocales visualization vorbis wifi winbind wxgtk1 xanim xine xml2 xmms xosd xpm xscreensaver xv xvid xvmc zlib elibc_glibc kernel_linux userland_GNU"
Unset:  ASFLAGS, CTARGET, EMERGE_DEFAULT_OPTS, LDFLAGS, LINGUAS
Comment 1 Jory A. Pratt 2006-05-07 06:47:13 UTC
Issue is resolved in beta3