Bug#720301: rkhunter: some shipped files are not included in md5sums

Andreas Beckmann anbe at debian.org
Tue Aug 20 08:43:13 UTC 2013


Package: rkhunter
Version: 1.4.0-3
Severity: important
User: debian-qa at lists.debian.org
Usertags: piuparts

Hi,

during a test with piuparts I noticed your package does not include
md5sums for all the files it ships:

  rkhunter: FILE WITHOUT MD5SUM /var/lib/rkhunter/db/backdoorports.dat
  rkhunter: FILE WITHOUT MD5SUM /var/lib/rkhunter/db/i18n/cn
  rkhunter: FILE WITHOUT MD5SUM /var/lib/rkhunter/db/i18n/de
  rkhunter: FILE WITHOUT MD5SUM /var/lib/rkhunter/db/i18n/en
  rkhunter: FILE WITHOUT MD5SUM /var/lib/rkhunter/db/i18n/zh
  rkhunter: FILE WITHOUT MD5SUM /var/lib/rkhunter/db/i18n/zh.utf8
  rkhunter: FILE WITHOUT MD5SUM /var/lib/rkhunter/db/mirrors.dat
  rkhunter: FILE WITHOUT MD5SUM /var/lib/rkhunter/db/programs_bad.dat
  rkhunter: FILE WITHOUT MD5SUM /var/lib/rkhunter/db/suspscan.dat

If these files are intended to be modified, they should be managed by
maintainer scripts instead of being shipped.
Currently they will be overwritten on every upgrade.


Andreas



More information about the forensics-devel mailing list