Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
For bugs related to Red Hat Enterprise Linux 5 product line. The current stable release is 5.10. For Red Hat Enterprise Linux 6 and above, please visit Red Hat JIRA https://issues.redhat.com/secure/CreateIssue!default.jspa?pid=12332745 to report new issues.

Bug 957752

Summary: Use absolute path when calling scl_enabled
Product: Red Hat Enterprise Linux 5 Reporter: Jan Zeleny <jzeleny>
Component: scl-utilsAssignee: Jan Zeleny <jzeleny>
Status: CLOSED ERRATA QA Contact: Lukáš Zachar <lzachar>
Severity: high Docs Contact:
Priority: unspecified    
Version: 5.9CC: drieden
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: scl-utils-20120927-7.el5 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
: 957754 (view as bug list) Environment:
Last Closed: 2013-09-30 22:05:38 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 957754    

Description Jan Zeleny 2013-04-29 13:06:39 UTC
If PATH is not set as scl-utils expect it, calling scl enable ... produces "command not found" error. This is caused by scl utility calling the command without absolute path, relying on the PATH that user has set. This is dangerous both from functionality and security perspective.

Comment 1 RHEL Program Management 2013-04-29 13:17:33 UTC
This request was evaluated by Red Hat Product Management for inclusion
in a Red Hat Enterprise Linux release.  Product Management has
requested further review of this request by Red Hat Engineering, for
potential inclusion in a Red Hat Enterprise Linux release for currently
deployed products.  This request is not yet committed for inclusion in
a release.

Comment 5 errata-xmlrpc 2013-09-30 22:05:38 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2013-1303.html