Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 131068

Summary: insecure RUNPATH in perl-core/Storable-2.15
Product: Gentoo Security Reporter: plimpton <joel>
Component: Runpath IssuesAssignee: Gentoo Linux bug wranglers <bug-wranglers>
Status: RESOLVED INVALID    
Severity: normal    
Priority: High    
Version: unspecified   
Hardware: x86   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---

Description plimpton 2006-04-24 00:23:56 UTC
Installing /var/tmp/portage/Storable-2.15/image/usr/lib/perl5/vendor_perl/5.8.5/i686-linux/auto/Storable/nstore.al
Writing /var/tmp/portage/Storable-2.15/image//usr/lib/perl5/vendor_perl/5.8.5/i686-linux/auto/Storable/.packlist
Appending installation info to /var/tmp/portage/Storable-2.15/image//usr/lib/perl5/5.8.5/i686-linux/perllocal.pod
man:
prepallstrip:
strip: i686-pc-linux-gnu-strip --strip-unneeded
   usr/lib/perl5/vendor_perl/5.8.5/i686-linux/auto/Storable/Storable.so
scanelf: rpath_security_checks(): Security problem NULL DT_RPATH in /var/tmp/portage/Storable-2.15/image//usr/lib/perl5/vendor_perl/5.8.5/i686-linux/auto/Storable/Storable.so
scanelf: rpath_security_checks(): Security problem NULL DT_RUNPATH in /var/tmp/portage/Storable-2.15/image//usr/lib/perl5/vendor_perl/5.8.5/i686-linux/auto/Storable/Storable.so


-----------------------------------------------
emerge --info
-----------------------------------------------

Portage 2.0.54 (default-linux/x86/2005.0, gcc-3.3.5, glibc-2.3.4.20040808-r1,glibc-2.3.4.20041102-r1, 2.6.11-etelos-eas-r3 i686)
=================================================================
System uname: 2.6.11-etelos-eas-r3 i686 Intel(R) Pentium(R) 4 CPU 2.40GHz
Gentoo Base System version 1.4.16
dev-lang/python:     2.3.4-r1
sys-apps/sandbox:    1.2.12
sys-devel/autoconf:  2.13, 2.59-r6
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r1
sys-devel/binutils:  2.15.92.0.2-r7
sys-devel/libtool:   1.4.3-r4, 1.5.22
virtual/os-headers:  2.6.8.1-r2
ACCEPT_KEYWORDS="x86"
ACCEPT_LICENSE=""
ARCH="x86"
AUTOCLEAN="yes"
BASH_ENV="/etc/spork/is/not/valid/profile.env"
CATALINA_HOME="/opt/tomcat5"
CBUILD="i686-pc-linux-gnu"
CFLAGS="-O2 -mcpu=i686 -fomit-frame-pointer"
CHOST="i686-pc-linux-gnu"
CLASSPATH="."
CLEAN_DELAY="5"
CONFIG_PROTECT="/etc /usr/kde/2/share/config /usr/kde/3/share/config /usr/lib/X11/xkb /usr/lib/fax /usr/share/config /var/qmail/control /var/spool/fax/etc"
CONFIG_PROTECT_MASK="/etc/eselect/compiler /etc/gconf /etc/terminfo /etc/env.d"
CVS_RSH="ssh"
CXXFLAGS="-O2 -mcpu=i686 -fomit-frame-pointer"
DISTDIR="/usr/portage/distfiles"
EDITOR="/bin/nano"
ELIBC="glibc"
EMERGE_WARNING_DELAY="10"
FEATURES="autoconfig distlocks sandbox sfperms strict"
FETCHCOMMAND="/usr/bin/wget -t 5 --passive-ftp -P ${DISTDIR} ${URI}"
GCC_SPECS=""
GDK_USE_XFT="1"
GENTOO_MIRRORS="http://gentoo.ccccom.com http://mirror.tucdemonic.org/gentoo/ ftp://mirrors.tds.net/gentoo ftp://gentoo.ccccom.com"
G_BROKEN_FILENAMES="1"
HOME="/root"
HOSTNAME="eas-rivida"
INFODIR="/usr/share/info"
INFOPATH="/usr/share/info:/usr/share/binutils-data/i686-pc-linux-gnu/2.15.92.0.2/info:/usr/share/gcc-data/i686-pc-linux-gnu/3.3.5/info"
INPUTRC="/etc/inputrc"
JAVAC="/opt/sun-jdk-1.5.0.06/bin/javac"
JAVA_HOME="/opt/sun-jdk-1.5.0.06"
JDK_HOME="/opt/sun-jdk-1.5.0.06"
KERNEL="linux"
LESS="-R"
LESSOPEN="|lesspipe.sh %s"
LOGNAME="root"
MAIL="/var/mail/root"
MAKEOPTS="-j2"
MANPATH="/usr/share/man:/usr/local/share/man:/usr/share/binutils-data/i686-pc-linux-gnu/2.15.92.0.2/man:/usr/share/gcc-data/i686-pc-linux-gnu/3.3.5/man::/opt/sun-jdk-1.5.0.06/man"
OLDPWD="/root/backup"
OPENGL_PROFILE="xorg-x11"
PAGER="/usr/bin/less"
PATH="/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/opt/bin:/usr/i686-pc-linux-gnu/gcc-bin/3.3.5:/opt/sun-jdk-1.5.0.06/bin:/opt/sun-jdk-1.5.0.06/jre/bin"
PKGDIR="/usr/portage/packages"
PORTAGE_ARCHLIST="alpha amd64 arm hppa ia64 m68k mips ppc ppc64 ppc-macos s390 sh sparc x86 x86-fbsd"
PORTAGE_BINHOST_CHUNKSIZE="3000"
PORTAGE_CALLER="emerge"
PORTAGE_GID="250"
PORTAGE_MASTER_PID="909"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PRELINK_PATH=""
PRELINK_PATH_MASK=""
PS1="\[\033[01;31m\]\h \[\033[01;34m\]\W \$ \[\033[00m\]"
PWD="/root"
PYTHONPATH="/usr/lib/portage/pym"
RESUMECOMMAND="/usr/bin/wget -c -t 5 --passive-ftp -P ${DISTDIR} ${URI}"
RPMDIR="/usr/portage/rpm"
RSYNC_RETRIES="3"
RSYNC_TIMEOUT="180"
SHELL="/bin/bash"
SHLVL="1"
SSH_CLIENT="67.168.108.163 2442 22"
SSH_CONNECTION="67.168.108.163 2442 209.130.151.78 22"
SSH_TTY="/dev/pts/0"
SYNC="rsync://rsync.gentoo.org/gentoo-portage"
TERM="xterm"
USE="acl acpi apache2 apm arts avi bash-completion berkdb bidi bindist bitmap-fonts bzip2 caps cli crypt cups curl dba dri eds emboss encode expat fam fastcgi fbcon flash foomaticdb fortran gd gdbm gif gmp gstreamer gtk gtk2 imagemagic imap imlib ipv6 isdnlog java jpeg lcms libg++ libww libwww mad mbox mcal memlimit mhash mikmod ming mmx mng motif mp3 mpeg mysql nas ncurses nls ogg oggvorbis opengl oss pam pcre pdflib perl php plotutils png posix postgres pppd python quicktime readline reflection samba sasl sdl session slang sockets spell spl sse ssl svga tcpd tiff truetype truetype-fonts type1-fonts unicode usb vhosts vorbis wmf x86 xml xml2 xmms xorg xv zlib userland_GNU kernel_linux elibc_glibc"
USER="root"
USERLAND="GNU"
USE_EXPAND="FRITZCAPI_CARDS FCDSL_CARDS VIDEO_CARDS DVB_CARDS INPUT_DEVICES LINGUAS USERLAND KERNEL ELIBC"
XARGS="xargs -r"
XINITRC="/etc/X11/xinit/xinitrc"
_="/usr/bin/emerge"
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2006-04-24 00:27:01 UTC
Not portage.
Comment 2 Jakub Moc (RETIRED) gentoo-dev 2006-04-24 00:28:16 UTC
Your perl version doesn't exist in portage, please don't report any bugs about perl until you've upgraded to latest stable perl and run perl-cleaner all.