Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 35842 - portage hacked?
Summary: portage hacked?
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: HPPA Porters
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2003-12-14 16:22 UTC by Chris C. Blockschmidt
Modified: 2011-10-30 22:39 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Chris C. Blockschmidt 2003-12-14 16:22:05 UTC
Reproducible: Always
Steps to Reproduce:
1.open /usr/portage/app-shells/bash/ChangeLog
2.
3.

Actual Results:  

  13 Dec 2003; root <root@gentoo.org> bash-2.05b-r7.ebuild:
  Marked stable on hppa.



Expected Results:  

  13 Dec 2003; somebody else <somebody_else@gentoo.org> bash-2.05b-r7.ebuild:
  Marked stable on hppa.



my dad and my cs teacher always tell me not to work as root because its 
dangerous!

or did this happen when the gentoo servers were hacked?

is it save to emerge bash?
Comment 1 Chris C. Blockschmidt 2003-12-14 16:24:47 UTC
he left a name!

/usr/portage/net-print/gqueue/ChangeLog
Comment 2 Donnie Berkholz (RETIRED) gentoo-dev 2003-12-14 16:42:22 UTC
This is what happens using echangelog as root without setting the env var ECHANGELOG_USER properly. Many developers commit as root, because in their minds it's more secure, someone would need root access to their computer to mess up Gentoo.

I recommend closing as invalid.
Comment 3 Seemant Kulleen (RETIRED) gentoo-dev 2003-12-14 16:52:44 UTC
guy -- I think someone on your team forgot to set their ECHANGELOG_USER variable
Comment 4 SpanKY gentoo-dev 2003-12-14 23:00:22 UTC
revision 1.24
date: 2003/12/14 00:09:35;  author: gmsoft;  state: Exp;  lines: +4 -1
Marked stable on hppa.
Comment 5 Guy Martin (RETIRED) gentoo-dev 2003-12-15 01:20:24 UTC
Sorry for this. I fixed the ChangeLog.

I figured that I forgot to set ECHANGELOG_USER after updating ~20 packages and I forget to correct this one.