Trusty will not install downloaded drivers with control files with incorrect owners

Bug #1304666 reported by cedial
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
software-center (Ubuntu)
New
Undecided
Unassigned

Bug Description

Trusty will not install downloaded drivers with bad MD5 sums even when told to do so. The Google Chrome package similarly will not install. This bug is the opposite of a security vulnerability; it is security overkill that turns the system into a boat anchor.

Earlier verions of Trusty and all earlier Ubuntu releases would honor a user's request to the software center request to "ignore and install". Clicking this button produces the message "The installation or removal of a software package failed."

This bug applies to the 14.04 daily build for 4/08 and a few earlier builds also.

ProblemType: Bug
DistroRelease: Ubuntu 14.04
Package: software-center 13.10-0ubuntu3
ProcVersionSignature: Ubuntu 3.13.0-23.45-generic 3.13.8
Uname: Linux 3.13.0-23-generic x86_64
ApportVersion: 2.14.1-0ubuntu1
Architecture: amd64
CurrentDesktop: Unity
Date: Tue Apr 8 15:49:13 2014
ExecutablePath: /usr/share/software-center/software-center
InstallationDate: Installed on 2014-04-08 (0 days ago)
InstallationMedia: Ubuntu 14.04 LTS "Trusty Tahr" - Daily amd64 (20140408)
InterpreterPath: /usr/bin/python2.7
PackageArchitecture: all
ProcEnviron:
 LANGUAGE=en_US
 PATH=(custom, no user)
 XDG_RUNTIME_DIR=<set>
 LANG=en_US.UTF-8
 SHELL=/bin/bash
SourcePackage: software-center
UpgradeStatus: No upgrade log present (probably fresh install)

Revision history for this message
cedial (cedial) wrote :
Revision history for this message
Seth Arnold (seth-arnold) wrote : Bug is not a security issue

Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privilege boundaries nor directly cause loss of data/privacy. Please feel free to report any other bugs you may find.

information type: Private Security → Public
summary: - Trusty will not install downloaded drivers with bad MD5 sums.
+ Trusty will not install downloaded drivers with control files with
+ incorrect owners
Revision history for this message
Seth Arnold (seth-arnold) wrote :

Note that the problem isn't the md5sums, the problem is that the owners of important files are incorrect:

Lintian check results for .../network-scan-linux-glibc2-x86_64.deb:
E: lexmark-network-scan: control-file-has-bad-owner md5sums build/build != root/root
E: lexmark-network-scan: control-file-has-bad-owner postinst build/build != root/root
E: lexmark-network-scan: control-file-has-bad-owner preinst build/build != root/root
E: lexmark-network-scan: control-file-has-bad-owner prerm build/build != root/root

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.