Overview

Request 875151 superseded

The packages cyrus-sasl and cyrus-sasl-saslauthd are built
The packages cyrus-sasl-bdb and cyrus-sasl-saslauthd-bdb are built
The packages cyrus-sasl and cyrus-sasl-saslauthd are built
The packages cyrus-sasl-bdb and cyrus-sasl-saslauthd-bdb are built
- CVE-2020-8032: cyrus-sasl: Local privilege escalation to root
due to insecure tmp file usage. (bsc#1180669)
Use /var/adm/update-scripts/ instead of /tmp. Clean up temporary
files.

The packages cyrus-sasl and cyrus-sasl-saslauthd are built
The packages cyrus-sasl-bdb and cyrus-sasl-saslauthd-bdb are built

Loading...

Dominique Leuenberger's avatar

Sorry for asking: but without a source change to the previous submitted revision:

what makes you believe it now builds?

it won't - and it can't

Maybe you should setup your devel project accordingly to SHOW you the error in the devel project. For one, you don't build the cyrus-sals-bdb flavor there (osc linkpac network cyrus-sasl network cyrus-sasl-bdb would help you show the issue)

The issue is rather simple: you have a dangling symlink of libsasl2.so to libsasl.so.3

libsasl2 is built as part of the MAIN package; the build script even explicitly rm -f libsasl2.so.3* (line 215 of cyrus-sasl-bdb.spec)

currently, there are two spec files that would be producing libsasl2-3: this is a no-go. only one package must produce the binary name at any given time.

Request History
Peter Varkoly's avatar

varkoly created request

The packages cyrus-sasl and cyrus-sasl-saslauthd are built
The packages cyrus-sasl-bdb and cyrus-sasl-saslauthd-bdb are built
The packages cyrus-sasl and cyrus-sasl-saslauthd are built
The packages cyrus-sasl-bdb and cyrus-sasl-saslauthd-bdb are built
- CVE-2020-8032: cyrus-sasl: Local privilege escalation to root
due to insecure tmp file usage. (bsc#1180669)
Use /var/adm/update-scripts/ instead of /tmp. Clean up temporary
files.

The packages cyrus-sasl and cyrus-sasl-saslauthd are built
The packages cyrus-sasl-bdb and cyrus-sasl-saslauthd-bdb are built


Factory Auto's avatar

factory-auto added opensuse-review-team as a reviewer

Please review sources


Factory Auto's avatar

factory-auto accepted review

Check script succeeded


Saul Goodman's avatar

licensedigger accepted review

ok


Richard Brown's avatar

RBrownSUSE set openSUSE:Factory:Staging:B as a staging project

Being evaluated by staging project "openSUSE:Factory:Staging:B"


Richard Brown's avatar

RBrownSUSE accepted review

Picked "openSUSE:Factory:Staging:B"


Peter Varkoly's avatar

varkoly superseded request

superseded by 875214

openSUSE Build Service is sponsored by