Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #952316 > unrolled thread

Bug#926060: lintian: portable-executable-missing-security-features false positives

Started byScott Kitterman <debian@kitterman.com>
First post2019-03-31 07:30 +0200
Last post2019-04-03 18:40 +0200
Articles 6 — 2 participants

Back to article view | Back to linux.debian.bugs.dist


Contents

  Bug#926060: lintian: portable-executable-missing-security-features false positives Scott Kitterman <debian@kitterman.com> - 2019-03-31 07:30 +0200
    Bug#926060: lintian: portable-executable-missing-security-features false positives "Chris Lamb" <lamby@debian.org> - 2019-04-01 11:00 +0200
      Bug#926060: lintian: portable-executable-missing-security-features false positives Scott Kitterman <debian@kitterman.com> - 2019-04-01 12:30 +0200
        Bug#926060: lintian: portable-executable-missing-security-features false positives "Chris Lamb" <lamby@debian.org> - 2019-04-01 12:40 +0200
          Bug#926060: lintian: portable-executable-missing-security-features false positives Scott Kitterman <debian@kitterman.com> - 2019-04-01 15:10 +0200
            Bug#926060: lintian: portable-executable-missing-security-features false positives "Chris Lamb" <lamby@debian.org> - 2019-04-03 18:40 +0200

#952316 — Bug#926060: lintian: portable-executable-missing-security-features false positives

FromScott Kitterman <debian@kitterman.com>
Date2019-03-31 07:30 +0200
SubjectBug#926060: lintian: portable-executable-missing-security-features false positives
Message-ID<xHBcB-11y-1@gated-at.bofh.it>
Package: lintian
Version: 2.11.0
Severity: normal

I'm reasonably confident that clamav testfiles don't need hardening features,
so [1] seems pretty pointless.

Scott K

[1] https://lintian.debian.org/maintainer/pkg-clamav-devel@lists.alioth.debian.org.html#clamav

clamav-testfiles

    E portable-executable-missing-security-features
        usr/share/clamav-testfiles/clam-aspack.exe ASLR DEP/NX SafeSEH
        usr/share/clamav-testfiles/clam-fsg.exe ASLR DEP/NX SafeSEH
        usr/share/clamav-testfiles/clam-nsis.exe ASLR DEP/NX
        usr/share/clamav-testfiles/clam-pespin.exe ASLR DEP/NX SafeSEH
        usr/share/clamav-testfiles/clam-petite.exe ASLR DEP/NX SafeSEH
        usr/share/clamav-testfiles/clam-upx.exe ASLR DEP/NX SafeSEH
        usr/share/clamav-testfiles/clam-wwpack.exe ASLR DEP/NX SafeSEH
        usr/share/clamav-testfiles/clam-yc.exe ASLR DEP/NX SafeSEH
        usr/share/clamav-testfiles/clam.ea05.exe ASLR DEP/NX
        usr/share/clamav-testfiles/clam.ea06.exe ASLR DEP/NX
        usr/share/clamav-testfiles/clam.exe ASLR DEP/NX
        usr/share/clamav-testfiles/clam_IScab_ext.exe ASLR DEP/NX
        usr/share/clamav-testfiles/clam_IScab_int.exe ASLR DEP/NX
        usr/share/clamav-testfiles/clam_ISmsi_ext.exe ASLR DEP/NX
        usr/share/clamav-testfiles/clam_ISmsi_int.exe ASLR DEP/NX

[toc] | [next] | [standalone]


#952506

From"Chris Lamb" <lamby@debian.org>
Date2019-04-01 11:00 +0200
Message-ID<xI0Xn-8hA-3@gated-at.bofh.it>
In reply to#952316
tags 926060 + moreinfo
thanks

Hi Scott,

> I'm reasonably confident that clamav testfiles don't need hardening features,
> so [1] seems pretty pointless.

I don't disagree at all here but I'm wondering how Lintian would be
able to detect that these are test files? Perhaps I'm missing
something. :)


Best wishes,

-- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org 🍥 chris-lamb.co.uk
       `-

[toc] | [prev] | [next] | [standalone]


#952519

FromScott Kitterman <debian@kitterman.com>
Date2019-04-01 12:30 +0200
Message-ID<xI2mw-O2-3@gated-at.bofh.it>
In reply to#952506
On Monday, April 01, 2019 04:45:44 AM Chris Lamb wrote:
> tags 926060 + moreinfo
> thanks
> 
> Hi Scott,
> 
> > I'm reasonably confident that clamav testfiles don't need hardening
> > features, so [1] seems pretty pointless.
> 
> I don't disagree at all here but I'm wondering how Lintian would be
> able to detect that these are test files? Perhaps I'm missing
> something. :)

I don't know.  I didn't look into how the test was implemented.  I thought it 
worthwhile to raise the point.  If the answer is that it requires special 
casing that you don't do in Linitan and we should override the test for this 
package as a result, that's fine.

Scott K

[toc] | [prev] | [next] | [standalone]


#952525

From"Chris Lamb" <lamby@debian.org>
Date2019-04-01 12:40 +0200
Message-ID<xI2w9-R9-5@gated-at.bofh.it>
In reply to#952519
Hi Scott,

> > > I'm reasonably confident that clamav testfiles don't need hardening
> > > features, so [1] seems pretty pointless.
> > 
> > I don't disagree at all here but I'm wondering how Lintian would be
> > able to detect that these are test files? Perhaps I'm missing
> > something. :)
> 
> I don't know.  I didn't look into how the test was implemented.

I guess my question was less about how the Lintian test is implemented
but rather how Lintian might potentially be able to determine
these .exe files are for internal testing purposes of your package.

> [if] we should override the test for this package as a result,
> that's fine.

… I strongly suspect this is the case, yeah. If you agree, please
go ahead and -done this issue. Thanks either way, naturally. :)


Best wishes,

-- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org 🍥 chris-lamb.co.uk
       `-

[toc] | [prev] | [next] | [standalone]


#952537

FromScott Kitterman <debian@kitterman.com>
Date2019-04-01 15:10 +0200
Message-ID<xI4Rj-2ox-1@gated-at.bofh.it>
In reply to#952525

On April 1, 2019 10:30:58 AM UTC, Chris Lamb <lamby@debian.org> wrote:
>Hi Scott,
>
>> > > I'm reasonably confident that clamav testfiles don't need
>hardening
>> > > features, so [1] seems pretty pointless.
>> > 
>> > I don't disagree at all here but I'm wondering how Lintian would be
>> > able to detect that these are test files? Perhaps I'm missing
>> > something. :)
>> 
>> I don't know.  I didn't look into how the test was implemented.
>
>I guess my question was less about how the Lintian test is implemented
>but rather how Lintian might potentially be able to determine
>these .exe files are for internal testing purposes of your package.
>
>> [if] we should override the test for this package as a result,
>> that's fine.
>
>… I strongly suspect this is the case, yeah. If you agree, please
>go ahead and -done this issue. Thanks either way, naturally. :)

These are all EICAR test files [1].  Generically these are all test files (I haven't checked, other packages may ship these to).  It would be at least slightly generic and not unreasonable to exclude any files with the EICAR test string from the test.

Scott K


[1] https://en.m.wikipedia.org/wiki/EICAR_test_file

[toc] | [prev] | [next] | [standalone]


#952888

From"Chris Lamb" <lamby@debian.org>
Date2019-04-03 18:40 +0200
Message-ID<xIR5D-6Fh-1@gated-at.bofh.it>
In reply to#952537
Hi Scott,

> >… I strongly suspect this is the case, yeah. If you agree, please
> >go ahead and -done this issue. Thanks either way, naturally. :)
> 
> These are all EICAR test files [1].  Generically these are all test 
> files (I haven't checked, other packages may ship these to).  It would 
> be at least slightly generic and not unreasonable to exclude any files 
> with the EICAR test string from the test.

Good idea. Unfortunately, your files don't actually actually include the
EICAR string :)


Best wishes,

-- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org 🍥 chris-lamb.co.uk
       `-

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web