Bug 743149

Summary: dbus-1: setuid binaries need to be position independent
Product: [openSUSE] openSUSE 12.2 Reporter: Ludwig Nussel <lnussel>
Component: OtherAssignee: Timo Hoenig <thoenig>
Status: RESOLVED FIXED QA Contact: E-mail List <qa-bugs>
Severity: Normal    
Priority: P5 - None CC: security-team
Version: Factory   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---
Bug Depends on:    
Bug Blocks: 744091    

Description Ludwig Nussel 2012-01-24 15:51:06 UTC
dbus-1 triggered the rpmlint check
"non-position-independent-executable" which means there are one or
more binaries that need to be compiled as position independent
executable.

To fix the issue add -fPIE to CFLAGS and -pie to LDFLAGS of the
binaries in question.
Comment 1 Daniel Lovasko 2012-02-06 10:14:15 UTC
fixed with submit 102851
Comment 2 Bernhard Wiedemann 2012-02-06 19:00:07 UTC
This is an autogenerated message for OBS integration:
This bug (743149) was mentioned in
https://build.opensuse.org/request/show/102935 Factory / dbus-1
Comment 3 Swamp Workflow Management 2012-10-31 15:11:03 UTC
openSUSE-SU-2012:1418-1: An update that solves 6 vulnerabilities and has 5 fixes is now available.

Category: security (moderate)
Bug References: 381621,394383,428963,432901,437293,443307,503074,697105,707817,743149,783657
CVE References: CVE-2006-6107,CVE-2008-0595,CVE-2008-3834,CVE-2008-4311,CVE-2010-4352,CVE-2012-3524
Sources used:
openSUSE 12.2 (src):    dbus-1-1.5.12-4.10.1, dbus-1-x11-1.5.12-4.10.1
openSUSE 12.1 (src):    dbus-1-1.5.8-2.10.1, dbus-1-x11-1.5.8-2.10.1
openSUSE 11.4 (src):    dbus-1-1.4.1-7.31.1, dbus-1-x11-1.4.1-7.31.1