Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 776991 - net-libs/courier-authlib-0.71.1 files with RUNPATH
Summary: net-libs/courier-authlib-0.71.1 files with RUNPATH
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Linux bug wranglers
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2021-03-18 00:29 UTC by Alessandro Barbieri
Modified: 2021-03-20 20:04 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alessandro Barbieri 2021-03-18 00:29:08 UTC
found with checksec

 * RUNPATH: RUNPATH /usr/libexec/courier-authlib/authdaemond
 * RUNPATH: RUNPATH /usr/lib64/courier-authlib/libauthcustom.so.0.0.0
 * RUNPATH: RUNPATH /usr/lib64/courier-authlib/libauthpipe.so.0.0.0
 * RUNPATH: RUNPATH /usr/lib64/courier-authlib/libauthsqlite.so.0.0.0
 * RUNPATH: RUNPATH /usr/lib64/courier-authlib/libauthpgsql.so.0.0.0
 * RUNPATH: RUNPATH /usr/lib64/courier-authlib/libcourierauthsaslclient.so.0.0.0
 * RUNPATH: RUNPATH /usr/lib64/courier-authlib/libauthshadow.so.0.0.0
 * RUNPATH: RUNPATH /usr/lib64/courier-authlib/libauthuserdb.so.0.0.0
 * RUNPATH: RUNPATH /usr/lib64/courier-authlib/libauthpam.so.0.0.0
 * RUNPATH: RUNPATH /usr/lib64/courier-authlib/libcourierauthsasl.so.0.0.0
 * RUNPATH: RUNPATH /usr/lib64/courier-authlib/libcourierauthcommon.so.0.0.0
 * RUNPATH: RUNPATH /usr/sbin/authenumerate
 * RUNPATH: RUNPATH /usr/sbin/authpasswd
 * RUNPATH: RUNPATH /usr/sbin/authtest
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-03-20 20:04:19 UTC
1) Please provide full output of whatever tool you're using. It's better to give more information than not.

2) Include emerge --info PACKAGE

3) Having a RUNPATH by itself is not a problem. These aren't insecure RUNPATHs. I think checksec is just telling you the value, it's not saying they're problematic. Portage already has checks for insecure RUNPATHs at install time.

If you're considering filing some mass bugs, it might be worth pinging one of us to check it over or ask in the first bug if e everything seems OK.