Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 141621

Summary: perl-core/Time-HiRes insecure RUNPATH's
Product: Gentoo Linux Reporter: Matthew Higginson <mhigginson1>
Component: New packagesAssignee: Gentoo Linux bug wranglers <bug-wranglers>
Status: RESOLVED TEST-REQUEST    
Severity: normal    
Priority: High    
Version: 2006.0   
Hardware: x86   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---

Description Matthew Higginson 2006-07-24 12:58:48 UTC
usr/lib/perl5/vendor_perl/5.8.7/i686-linux/auto/Time/HiRes/HiRes.so
scanelf: rpath_security_checks(): Security problem NULL DT_RPATH in /var/tmp/portage/Time-HiRes-1.82/image/usr/lib/perl5/vendor_perl/5.8.7/i686-linux/auto/Time/HiRes/HiRes.so
scanelf: rpath_security_checks(): Security problem NULL DT_RUNPATH in /var/tmp/portage/Time-HiRes-1.82/image/usr/lib/perl5/vendor_perl/5.8.7/i686-linux/auto/Time/HiRes/HiRes.so

QA Notice: the following files contain insecure RUNPATH's
 Please file a bug about this at http://bugs.gentoo.org/
 with the maintaining herd of the package.
 Summary: perl-core/Time-HiRes: insecure RPATH  usr/lib/perl5/vendor_perl/5.8.7/i686-linux/auto/Time/HiRes/HiRes.so
 usr/lib/perl5/vendor_perl/5.8.7/i686-linux/auto/Time/HiRes/HiRes.so

EMERGE --INFO Below

Portage 2.1-r1 (default-linux/x86/2006.0, gcc-3.3.5, glibc-2.3.4.20040808-r1, 2.6.16.2-gentoo i686)
=================================================================
System uname: 2.6.16.2-gentoo i686 AMD Athlon(tm) XP 2100+
Gentoo Base System version 1.6.12
app-admin/eselect-compiler: [Not Present]
dev-lang/python:     2.3.4-r1
dev-python/pycrypto: 2.0.1-r5
dev-util/ccache:     [Not Present]
dev-util/confcache:  [Not Present]
sys-apps/sandbox:    1.2.17
sys-devel/autoconf:  2.13, 2.59-r6
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.4
sys-devel/binutils:  2.15.92.0.2-r1
sys-devel/gcc-config: 1.3.11-r3
sys-devel/libtool:   1.5.10-r4
virtual/os-headers:  2.6.8.1-r2
ACCEPT_KEYWORDS="x86"
AUTOCLEAN="yes"
CBUILD="i686-pc-linux-gnu"
CFLAGS="-O2 -march=athlon-xp -fomit-frame-pointer"
CHOST="i686-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/kde/3.4/env /usr/kde/3.4/share/config /usr/kde/3.4/shutdown /usr/lib/X11/xkb /usr/share/config /var/bind /var/qmail/alias /var/qmail/control"
CONFIG_PROTECT_MASK="/etc/env.d /etc/gconf /etc/terminfo"
CXXFLAGS="-O2 -march=athlon-xp -fomit-frame-pointer"
DISTDIR="/usr/portage/distfiles"
FEATURES="autoconfig distlocks metadata-transfer sandbox sfperms strict"
GENTOO_MIRRORS="http://distfiles.gentoo.org http://distro.ibiblio.org/pub/linux/distributions/gentoo"
PKGDIR="/usr/portage/packages"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --delete-after --stats --timeout=180 --exclude='/distfiles' --exclude='/local' --exclude='/packages'"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
SYNC="rsync://rsync.gentoo.org/gentoo-portage"
USE="x86 X alsa apache2 apm arts avi berkdb bitmap-fonts cli crypt cups dlloader dri eds emboss encode esd foomaticdb fortran gdbm gif gnome gpm gstreamer gtk gtk2 imlib isdnlog jpeg kde libg++ libwww mad mikmod motif mp3 mpeg ncurses nls nptl nptlonly ogg opengl oss pam pcre pdflib perl png pppd python qt qt3 qt4 quicktime readline reflection sdl session spell spl tcpd truetype truetype-fonts type1-fonts udev unicode userlocales vorbis xml xmms xorg xv zlib elibc_glibc input_devices_keyboard input_devices_mouse input_devices_evdev kernel_linux userland_GNU"
Unset:  CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LANG, LC_ALL, LDFLAGS, LINGUAS, MAKEOPTS, PORTAGE_RSYNC_EXTRA_OPTS, PORTDIR_OVERLAY
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2006-07-24 14:09:16 UTC
Reopen if you can reproduce this w/ up-to-date perl (5.8.8-r2) - and unmerge ExtUtils-MakeMaker if you have it installed by some nasty accident.