Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 321607 - net-analyzer/rrdtool - insecure RUNPATHs: usr/lib/ruby/site_ruby/1.8/i686-linux/RRD.so
Summary: net-analyzer/rrdtool - insecure RUNPATHs: usr/lib/ruby/site_ruby/1.8/i686-lin...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: High QA (vote)
Assignee: Gentoo Netmon project
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2010-05-26 23:10 UTC by Jeroen Roovers (RETIRED)
Modified: 2014-05-19 18:35 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
net-analyzer-rrdtool-1.4.3:20100526-230125.log (20100526-230125.log,53.68 KB, text/plain)
2010-05-26 23:11 UTC, Jeroen Roovers (RETIRED)
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Jeroen Roovers (RETIRED) gentoo-dev 2010-05-26 23:10:17 UTC
Thu May 27 01:09:22 CEST 2010
Portage 2.2_rc67 (default/linux/x86/10.0/desktop, gcc-4.3.4, glibc-2.10.1-r1, 2.6.31-gentoo-r6-JeR i686)
=================================================================
                        System Settings
=================================================================
System uname: Linux-2.6.31-gentoo-r6-JeR-i686-AMD_Athlon-tm-_XP_2500+-with-gentoo-1.12.13
Timestamp of tree: Wed, 26 May 2010 15:15:03 +0000
distcc 3.1 i686-pc-linux-gnu [disabled]
ccache version 2.4 [disabled]
app-shells/bash:     4.0_p37
dev-java/java-config: 2.1.10
dev-lang/python:     2.6.4-r1
dev-python/pycrypto: 2.1.0_beta1
dev-util/ccache:     2.4-r7
dev-util/cmake:      2.6.4-r3
sys-apps/baselayout: 1.12.13
sys-apps/sandbox:    2.2
sys-devel/autoconf:  2.13, 2.65
sys-devel/automake:  1.4_p6-r1, 1.7.9-r2, 1.9.6-r3, 1.11.1
sys-devel/binutils:  2.18-r3
sys-devel/gcc:       4.3.4
sys-devel/gcc-config: 1.4.1
sys-devel/libtool:   2.2.7b
virtual/os-headers:  2.6.30-r1
ACCEPT_KEYWORDS="x86"
ACCEPT_LICENSE="*"
CBUILD="i686-pc-linux-gnu"
CFLAGS="-O2 -pipe -Wall -march=athlon-xp"
CHOST="i686-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/share/X11/app-defaults/XTerm /usr/share/X11/app-defaults/XTerm-color /usr/share/X11/xkb"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/env.d /etc/env.d/java/ /etc/eselect/postgresql /etc/fonts/fonts.conf /etc/gconf /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo /etc/texmf/language.dat.d /etc/texmf/language.def.d /etc/texmf/updmap.d /etc/texmf/web2c"
CXXFLAGS="-O2 -pipe -Wall -march=athlon-xp"
DISTDIR="/newaches/gentoo/distfiles"
FEATURES="assume-digests autoaddcvs buildpkg cvs distlocks fixpackages metadata-transfer news notitles parallel-fetch protect-owned sandbox sfperms splitdebug strict test-fail-continue unmerge-logs unmerge-orphans userfetch userpriv"
GENTOO_MIRRORS="http://ftp.snt.utwente.nl/pub/os/linux/gentoo http://gentoo.tiscali.nl/ "
LANG="en_GB"
LC_ALL="en_GB.UTF-8"
LDFLAGS="-Wl,-O1 -Wl,--hash-style=gnu -Wl,--as-needed"
LINGUAS="en en_GB nl"
MAKEOPTS="-j2"
PKGDIR="/keeps/gentoo/packages/astrid"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/keeps/gentoo/portage"
PORTDIR_OVERLAY="/keeps/gentoo/local"
SYNC="rsync://rsync.europe.gentoo.org/gentoo-portage"
USE="3dnow 3dnowext X a52 aac aalib acpi alsa asf audiofile bash-completion berkdb bl boost branding bzip2 cairo cdda cddb cdio cdparanoia cdr chroot cli cracklib crypt cscope css cups curl custom-cflags custom-cxxflags cxx dbus dga dillo divx dri dts dv dvd dvdr dvdread edl elf emboss encode exif fame fbcon ffmpeg flac flash fontconfig fontforge foomaticdb fortran freetype gdbm geoip ggi gif gimpprint glib glitz glut gmedia gnokii gnutls gpm grp gs gtk gtk2 hog iconv id3tag idn imlib inkjar ipv6 jingle jpeg lcms libcaca libsamplerate live lm_sensors logrotate lua lzo mad matroska midi mikmod mjpeg mmx mng modplug modules mozilla mozsvg mozxmlterm mp3 mp4 mpeg mplayer mudflap multislot musepack mvl ncurses nethack network network-cron nforce2 nl nls nptl nptlonly nsplugin nss nvidia offensive ogg opengl openmp openssl optimisememory pam pango pcre pda pdf perl physfs plotutils png ppds pppd python qpak qt3support quicktime readline realmedia reflection rtc rtsp ruby samba savedconfig server session sftplogging shout skins smux snmp speex spell spl sse ssl stream svg sysfs syslog tcpd test tetex tga theora threads tiff truetype unicode upnp usb userlocales utils v4l v4l2 vcd vidix vim visualizer vlm vorbis wad web webdav-neon win32codecs winbind wmp x264 x86 xanim xcb xcomposite xml xml2 xorg xosd xterm-color xulrunner xv xvid xvmc zlib" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1 emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mmap_emul mulaw multi null plug rate route share shm softvol" APACHE2_MODULES="actions alias auth_basic authn_alias authn_anon authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache dav dav_fs dav_lock deflate dir disk_cache env expires ext_filter file_cache filter headers include info log_config logio mem_cache mime mime_magic negotiation rewrite setenvif speling status unique_id userdir usertrack vhost_alias" ELIBC="glibc" INPUT_DEVICES="keyboard mouse evdev wacom" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LINGUAS="en en_GB nl" RUBY_TARGETS="ruby18" USERLAND="GNU" VIDEO_CARDS="nvidia via" XTABLES_ADDONS="quota2 psd pknock lscan length2 ipv4options ipset ipp2p iface geoip fuzzy condition tee tarpit sysrq steal rawnat logmark ipmark dhcpmac delude chaos account" 
Unset:  CPPFLAGS, CTARGET, EMERGE_DEFAULT_OPTS, FFLAGS, INSTALL_MASK, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS

=================================================================
                        Package Settings
=================================================================

net-analyzer/rrdtool-1.4.2 was built with the following:
USE="lua perl python ruby test -doc -rrdcgi -tcl"
Comment 1 Jeroen Roovers (RETIRED) gentoo-dev 2010-05-26 23:11:20 UTC
Created attachment 233063 [details]
net-analyzer-rrdtool-1.4.3:20100526-230125.log
Comment 2 Hans de Graaff gentoo-dev Security 2014-05-19 18:35:08 UTC
This problem is fixed with the introduction of a separate package for the rrdtool ruby bindings: dev-ruby/rrdtool-bindings. This is used in net-analyzer/rrdtool-1.4.8-r1 and up.