Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 666404 - sys-apps/man-db-2.8.4 - system executables owned by nonzero uid
Summary: sys-apps/man-db-2.8.4 - system executables owned by nonzero uid
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo's Team for Core System packages
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-09-17 11:52 UTC by Francesco Turco
Modified: 2019-01-06 15:11 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments
emerge-info.txt (emerge-info.txt,5.73 KB, text/plain)
2018-09-17 11:52 UTC, Francesco Turco
Details
build.log.xz (build.log.xz,18.93 KB, application/x-xz)
2018-09-17 11:54 UTC, Francesco Turco
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Francesco Turco 2018-09-17 11:52:46 UTC
Created attachment 547084 [details]
emerge-info.txt

Portage reports the following QA issue when emerging sys-apps/man-db-2.8.4:

> * system executables owned by nonzero uid:
> *   /usr/bin/man
> *   /usr/bin/mandb

On my system:

> $ ls -l /usr/bin/{man,mandb}
> -rwsr-s--x 1 man man 112464 Sep 17 13:48 /usr/bin/man
> -rwsr-s--x 1 man man 134928 Sep 17 13:48 /usr/bin/mandb
Comment 1 Francesco Turco 2018-09-17 11:54:02 UTC
Created attachment 547086 [details]
build.log.xz
Comment 2 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2018-09-17 12:28:17 UTC
See https://bugs.gentoo.org/662438#c3
Comment 3 Larry the Git Cow gentoo-dev 2019-01-06 15:11:50 UTC
The bug has been closed via the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=afd4c6fd6980ca985387496bfe16588e9a387d1c

commit afd4c6fd6980ca985387496bfe16588e9a387d1c
Author:     Lars Wendler <polynomial-c@gentoo.org>
AuthorDate: 2019-01-06 15:04:51 +0000
Commit:     Lars Wendler <polynomial-c@gentoo.org>
CommitDate: 2019-01-06 15:11:40 +0000

    sys-apps/man-db: Bump to version 2.8.5
    
    Attempt to fix root privilege escalation.
    
    Bug: https://bugs.gentoo.org/662438
    Closes: https://bugs.gentoo.org/666404
    Package-Manager: Portage-2.3.54, Repoman-2.3.12
    Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>

 sys-apps/man-db/Manifest             |   1 +
 sys-apps/man-db/files/man-db.cron-r1 |  11 ++++
 sys-apps/man-db/man-db-2.8.5.ebuild  | 121 +++++++++++++++++++++++++++++++++++
 3 files changed, 133 insertions(+)

Additionally, it has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=59d4f75abd7dc6b691a95b5447133922ff09ea3f

commit 59d4f75abd7dc6b691a95b5447133922ff09ea3f
Author:     Lars Wendler <polynomial-c@gentoo.org>
AuthorDate: 2019-01-06 15:10:21 +0000
Commit:     Lars Wendler <polynomial-c@gentoo.org>
CommitDate: 2019-01-06 15:11:41 +0000

    sys-apps/man-db: Synced live ebuild.
    
    Attempt to fix root privilege escalation.
    
    Bug: https://bugs.gentoo.org/662438
    Bug: https://bugs.gentoo.org/666404
    Package-Manager: Portage-2.3.54, Repoman-2.3.12
    Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>

 sys-apps/man-db/man-db-9999.ebuild | 17 ++++++++---------
 1 file changed, 8 insertions(+), 9 deletions(-)