misc/168385: every port has vulnerabilities in case of locale problems

Michael Stapelberg michael+freebsd at stapelberg.de
Sun May 27 18:00:30 UTC 2012


>Number:         168385
>Category:       misc
>Synopsis:       every port has vulnerabilities in case of locale problems
>Confidential:   no
>Severity:       non-critical
>Priority:       medium
>Responsible:    freebsd-bugs
>State:          open
>Quarter:        
>Keywords:       
>Date-Required:
>Class:          sw-bug
>Submitter-Id:   current-users
>Arrival-Date:   Sun May 27 18:00:08 UTC 2012
>Closed-Date:
>Last-Modified:
>Originator:     Michael Stapelberg
>Release:        7.4-RELEASE-p2
>Organization:
>Environment:
FreeBSD rzl.uugrn.org 7.4-RELEASE-p2 FreeBSD 7.4-RELEASE-p2 #3: Tue Aug  9 23:04:35 CEST 2011     root at top.uugrn.org:/usr/obj/usr/src/sys/TOP  i386

>Description:
See "how to repeat the problem"
>How-To-Repeat:
rzl# locale -a | grep en_DK
rzl# echo $LC_TIME         
en_DK.UTF-8
rzl# cd /usr/ports/biology/chemeq 
rzl# make        
===>  chemeq-1.50_1 has known vulnerabilities:
tar: Failed to set default locale
tar: Failed to set default locale
tar: Failed to set default locale
tar: Failed to set default locale
tar: Failed to set default locale
tar: Failed to set default locale
tar: Failed to set default locale
tar: Failed to set default locale
tar: Failed to set default locale
=> Please update your ports tree and try again.
*** Error code 1

Stop in /usr/ports/biology/chemeq.

rzl# unset LC_TIME
rzl# make
===>  License check disabled, port has not defined LICENSE
=> chemeq_1.5.tar.gz doesn't seem to exist in /data/ports/distfiles//.
=> Attempting to fetch /usr/ports/distfiles//chemeq_1.5.tar.gz
fetch: /usr/ports/distfiles//chemeq_1.5.tar.gz: No such file or directory
=> Attempting to fetch http://download.gna.org/chemeq/chemeq-1.5/chemeq_1.5.tar.gz
chemeq_1.5.tar.gz                             100% of   27 kB  459 kBps

>Fix:


>Release-Note:
>Audit-Trail:
>Unformatted:


More information about the freebsd-bugs mailing list