Bug#587392: fuzzyocr: Tainted data in Misc.pm

2010-06-28 Thread Gabor Kiss
Package: fuzzyocr
Version: 3.5.1+svn135-1.1
Severity: normal

Maillog contains lines like this:

Jun 28 09:34:32 bolha amavis[3921]: (03921-11) (!)SA error: FuzzyOcr: Error 
running preprocessor(ppmtopgm): /usr/bin/ppmtopgm
Jun 28 09:34:32 bolha amavis[3921]: (03921-11) SA warn: FuzzyOcr: Errors in 
Scanset ocrad-decolorize-invert
Jun 28 09:34:32 bolha amavis[3921]: (03921-11) SA warn: FuzzyOcr: Return code: 
2048, Error: save_execute: Insecure dependency in exec while running with -T 
switch at /usr/share/perl5/FuzzyOcr/Misc.pm line 188.
Jun 28 09:34:32 bolha amavis[3921]: (03921-11) SA warn: FuzzyOcr: save_execute: 
Insecure dependency in exec while running with -T switch at 
/usr/share/perl5/FuzzyOcr/Misc.pm line 188.
Jun 28 09:34:32 bolha amavis[3921]: (03921-11) SA warn: FuzzyOcr: Skipping 
scanset because of errors, trying next...
Jun 28 09:34:32 bolha amavis[3921]: (03921-11) (!)SA error: FuzzyOcr: Error runn
ing preprocessor(ppmtopgm): /usr/bin/ppmtopgm
Jun 28 09:34:32 bolha amavis[3921]: (03921-11) SA warn: FuzzyOcr: Errors in 
Scanset ocrad-decolorize
Jun 28 09:34:32 bolha amavis[3921]: (03921-11) SA warn: FuzzyOcr: Return code: 
2048, Error: save_execute: Insecure dependency in exec while running with -T 
switch at /usr/share/perl5/FuzzyOcr/Misc.pm line 188.
Jun 28 09:34:32 bolha amavis[3921]: (03921-11) SA warn: FuzzyOcr: save_execute: 
Insecure dependency in exec while running with -T switch at 
/usr/share/perl5/FuzzyOcr/Misc.pm line 188.
Jun 28 09:34:32 bolha amavis[3921]: (03921-11) SA warn: FuzzyOcr: Skipping 
scanset because of errors, trying next...
Jun 28 09:34:32 bolha amavis[3921]: (03921-11) (!)SA error: FuzzyOcr: Unable to 
read output from 
/var/lib/amavis/tmp/.spamassassin3921sBkCR4tmp/scanset.tesseract.out.txt for 
scanset tesseract
Jun 28 09:34:32 bolha amavis[3921]: (03921-11) SA warn: FuzzyOcr: Errors in 
Scanset tesseract
Jun 28 09:34:32 bolha amavis[3921]: (03921-11) SA warn: FuzzyOcr: Return code: 
2048, Error: save_execute: Insecure dependency in exec while running with -T 
switch at /usr/share/perl5/FuzzyOcr/Misc.pm line 188.
Jun 28 09:34:32 bolha amavis[3921]: (03921-11) SA warn: FuzzyOcr: save_execute: 
Insecure dependency in exec while running with -T switch at 
/usr/share/perl5/FuzzyOcr/Misc.pm line 188.
Jun 28 09:34:32 bolha amavis[3921]: (03921-11) SA warn: FuzzyOcr: Skipping 
scanset because of errors, trying next...

This is an Amavisd+Spamassasin dedicated spamfilter host.
Actually I don't know if amavisd-new or spamassasin or fuzzyocr was
who forgot to sanitize input data.

Gabor

-- System Information:
Debian Release: 5.0.5
  APT prefers stable
  APT policy: (700, 'stable'), (500, 'proposed-updates')
Architecture: i386 (i686)

Kernel: Linux 2.6.26-2-686 (SMP w/4 CPU cores)
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)
Shell: /bin/sh linked to /bin/bash

Versions of packages fuzzyocr depends on:
ii  gifsicle1.51-1   Tool for manipulating GIF images
ii  gocr0.45-2   A command line OCR
ii  libdbd-mysql-perl   4.007-1+lenny1   A Perl5 database interface to the 
ii  libmldbm-sync-perl  0.30-2   Perl module for safe concurrent ac
ii  libstring-approx-perl   3.26-1   Perl extension for approximate mat
ii  libtie-cache-perl   0.17-4   perl Tie::Cache - LRU Cache in Mem
ii  libungif-bin4.1.6-6  library for GIF images (transition
ii  netpbm  2:10.0-12+lenny1 Graphics conversion tools
ii  ocrad   0.17-3   Optical Character Recognition prog
ii  perl [libdigest-md5-per 5.10.0-19lenny2  Larry Wall's Practical Extraction 
ii  spamassassin3.3.1-1~bpo50+1  Perl-based spam filter using text 
ii  tesseract-ocr-eng   2.00-1   tesseract-ocr language files for E

fuzzyocr recommends no packages.

fuzzyocr suggests no packages.

Other:
ii  amavisd-new 1:2.6.4-1~bpo50+1 Interface betwe

-- no debconf information



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#587392: fuzzyocr: Tainted data in Misc.pm

2010-06-28 Thread Francois Marier
Hi Gabor,


On 2010-06-28 at 11:09:18, Gabor Kiss wrote:
 Package: fuzzyocr
 Version: 3.5.1+svn135-1.1

Can you try again with version 3.6.0-3 of the fuzzyocr package?

The last two versions fixed a number of untaint-related issues, so you might
find your problem resolved in that version.

Cheers,
Francois



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#587392: fuzzyocr: Tainted data in Misc.pm

2010-06-28 Thread Kiss Gabor (Bitman)
 Can you try again with version 3.6.0-3 of the fuzzyocr package?

It seems to be better. :-)

Thanks

Gabor



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org