Bug 2020015 - rkhunter shows warning message about a hidden file
Summary: rkhunter shows warning message about a hidden file
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: rkhunter
Version: 35
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Kevin Fenzi
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2021-11-03 20:43 UTC by Markus Teuber
Modified: 2022-06-03 12:08 UTC (History)
6 users (show)

Fixed In Version: rkhunter-1.4.6-14.fc35
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-11-10 02:54:36 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Markus Teuber 2021-11-03 20:43:47 UTC
Description of problem:
rkhunter shows warning message about a hidden file. I guess it should not.

Version-Release number of selected component (if applicable):
1.4.6

How reproducible:


Steps to Reproduce:
1. rkhunter --update
2. rkhunter --propupd
3. rkhunter --check --skip-keypress
4. check the log-file (/var/log/rkhunter/rkhunter.log), and/or mail if configured.

Actual results:
Warnung: Versteckte Datei gefunden: /usr/share/man/man5/.containerignore.5.gz: gzip compressed data, max compression, from Unix, truncated

Expected results:
no message

Additional info:

Comment 1 Nerijus Baliūnas 2021-11-04 08:43:16 UTC
# rpm -qf /usr/share/man/man5/.containerignore.5.gz
containers-common-1-32.fc35.noarch

Comment 2 Kevin Fenzi 2021-11-06 17:28:00 UTC
Thanks for the report, will work on a update soon.

Comment 3 Fedora Update System 2021-11-06 17:52:45 UTC
FEDORA-2021-7575a5ecf7 has been submitted as an update to Fedora 35. https://bodhi.fedoraproject.org/updates/FEDORA-2021-7575a5ecf7

Comment 4 Fedora Update System 2021-11-07 02:09:52 UTC
FEDORA-2021-7575a5ecf7 has been pushed to the Fedora 35 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2021-7575a5ecf7`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2021-7575a5ecf7

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 5 Markus Teuber 2021-11-07 08:46:32 UTC
Works well. Thank you for fixing this.

Comment 6 Fedora Update System 2021-11-10 02:54:36 UTC
FEDORA-2021-7575a5ecf7 has been pushed to the Fedora 35 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 7 Brian Morrison 2022-01-20 14:26:56 UTC
Well, I have the new package on one of my Fedora 35 systems and every day I get this in my rkhunter log:

---------------------- Start Rootkit Hunter Scan ----------------------
Warning: Hidden file found: /usr/share/man/man5/.containerignore.5.gz: gzip compressed data, max compression, from Unix, truncated

----------------------- End Rootkit Hunter Scan -----------------------

No idea why the fix doesn't work here

$ rpm -qi rkhunter
Name        : rkhunter
Version     : 1.4.6
Release     : 14.fc35
Architecture: noarch
Install Date: Sat 06 Nov 2021 18:47:09 GMT
Group       : Unspecified
Size        : 868715
License     : GPLv2+
Signature   : (none)
Source RPM  : rkhunter-1.4.6-14.fc35.src.rpm
Build Date  : Sat 06 Nov 2021 17:46:45 GMT
Build Host  : buildvm-s390x-22.s390.fedoraproject.org
Packager    : Fedora Project
Vendor      : Fedora Project
URL         : http://rkhunter.sourceforge.net/
Bug URL     : https://bugz.fedoraproject.org/rkhunter
Summary     : A host-based tool to scan for rootkits, backdoors and local exploits
Description :
Rootkit Hunter (RKH) is an easy-to-use tool which checks
computers running UNIX (clones) for the presence of rootkits
and other unwanted tools.

Comment 8 Brian Morrison 2022-01-20 14:34:57 UTC
Ah, OK, found the rpmnew file on the errant system. No idea how the original .conf got modified.

Sorry for the noise.

Comment 9 Quien Sabe 2022-06-02 11:47:41 UTC
I see that this issue is closed, but I am seeing it on Fedora 36 which I just recently installed.

Comment 10 Kevin Fenzi 2022-06-02 21:21:57 UTC
What version of rkhunter do you have? (rpm -q rkhunter) 

Do you have a /etc/rkhunter.conf.rpmnew file?

Comment 11 Quien Sabe 2022-06-03 12:08:28 UTC
No, but when reading your reply it dawned on me that my system config tools manage the /etc/rkhunter.conf file, so since it is my first experience with Fedora in years I simple needed to define the Fedora specific exceptions there.

Sorry for the noise. :)


Note You need to log in before you can comment on or make changes to this bug.