Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 119715 - net-p2p/sancho-bin problem with relative DT_RPATH '.:./lib'
Summary: net-p2p/sancho-bin problem with relative DT_RPATH '.:./lib'
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Runpath Issues (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo net-p2p team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks: 81745
  Show dependency tree
 
Reported: 2006-01-20 11:32 UTC by Krzysztof Pawlik (RETIRED)
Modified: 2006-09-28 04:28 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Krzysztof Pawlik (RETIRED) gentoo-dev 2006-01-20 11:32:43 UTC
Merge of net-p2p/sancho-bin-0.9.4.56:

strip: i686-pc-linux-gnu-strip --strip-unneeded
   /opt/sancho/lib/libswt-mozilla-gtk-3218.so
   /opt/sancho/lib/libgcj.so.6.0.0
   /opt/sancho/lib/libswt-gtk-3218.so
   /opt/sancho/lib/libgcc_s.so.1
   /opt/sancho/lib/libswt-atk-gtk-3218.so
   /opt/sancho/lib/libswt-pi-gtk-3218.so
   /opt/sancho/lib/libswt-cairo-gtk-3218.so
   /opt/sancho/lib/libswt-gnome-gtk-3218.so
   /opt/sancho/lib/libswt-glx-gtk-3218.so
   /opt/sancho/lib/libswt-awt-gtk-3218.so
   /opt/sancho/sancho-bin
scanelf: rpath_security_checks(): Security problem with relative DT_RPATH '.:./lib' in /var/tmp/portage/sancho-bin-0.9.4.56/image//opt/sancho/sancho-bin
scanelf: rpath_security_checks(): Security problem with relative DT_RPATH './lib' in /var/tmp/portage/sancho-bin-0.9.4.56/image//opt/sancho/sancho-bin

Issue similiar to bug 117063.
Comment 1 Tavis Ormandy (RETIRED) gentoo-dev 2006-01-20 11:43:46 UTC
the sancho wrapper script cd's to /opt/bin before executing, so not possible to exploit this unless someone executes it directly.

nevertheless, should be fixed.
Comment 2 solar (RETIRED) gentoo-dev 2006-03-05 08:03:06 UTC
The next ~arch portage revision will auto repair evil rpaths and not bail. 
Maintainers should still fix the packages they maintain as portage will only die
with FEATURES=stricter (but that is a maintainer & QA problem) no longer security@

http://bugs.gentoo.org/show_bug.cgi?id=124962
Comment 3 Jakub Moc (RETIRED) gentoo-dev 2006-09-21 03:45:47 UTC
No longer a security issue with current stable portage, re-assigning to maintainer.
Comment 4 Krzysztof Pawlik (RETIRED) gentoo-dev 2006-09-28 04:28:34 UTC
As it's a not a security issue anymore