Whitelist more expectedly setuid executables; fixes #646455.
This commit is contained in:
parent
db3d04e628
commit
8480e39802
@ -337,6 +337,13 @@ addFilter("filename-too-long-for-joliet")
|
|||||||
addFilter("symlink-should-be-")
|
addFilter("symlink-should-be-")
|
||||||
addFilter("dangling-\S*symlink /usr/share/doc/HTML/\S+/common .+/common$")
|
addFilter("dangling-\S*symlink /usr/share/doc/HTML/\S+/common .+/common$")
|
||||||
addFilter("hidden-file-or-dir .*/man5/\.k5login\.5[^/]+$")
|
addFilter("hidden-file-or-dir .*/man5/\.k5login\.5[^/]+$")
|
||||||
# TODO: more whitelisted executables, https://bugzilla.redhat.com/496737
|
|
||||||
addFilter("krb5-workstation.+ (setuid-binary|non-standard-executable-perm) /usr/kerberos/bin/ksu (root )?04755")
|
|
||||||
addFilter("blender.+ (wrong-script-interpreter|non-executable-script) .+/blender/.+\.py.*BPY.*")
|
addFilter("blender.+ (wrong-script-interpreter|non-executable-script) .+/blender/.+\.py.*BPY.*")
|
||||||
|
# https://bugzilla.redhat.com/496737, https://bugzilla.redhat.com/646455
|
||||||
|
for pkg, exe in (("coreutils", "/bin/su"),
|
||||||
|
("krb5-workstation", "/usr/kerberos/bin/ksu"),
|
||||||
|
("passwd", "/usr/bin/passwd"),
|
||||||
|
("sudo", "/usr/bin/sudo(edit)?"),
|
||||||
|
("upstart", "/sbin/initctl"),
|
||||||
|
("usermode", "/usr/sbin/userhelper")):
|
||||||
|
addFilter("%s.* (setuid-binary|non-standard-executable-perm) %s (root )?04"
|
||||||
|
% (pkg, exe))
|
||||||
|
@ -78,6 +78,9 @@ rm -rf $RPM_BUILD_ROOT
|
|||||||
|
|
||||||
|
|
||||||
%changelog
|
%changelog
|
||||||
|
* Mon Nov 1 2010 Ville Skyttä <ville.skytta@iki.fi>
|
||||||
|
- Whitelist more expectedly setuid executables; fixes #646455.
|
||||||
|
|
||||||
* Thu Aug 19 2010 Ville Skyttä <ville.skytta@iki.fi> - 0.99-1
|
* Thu Aug 19 2010 Ville Skyttä <ville.skytta@iki.fi> - 0.99-1
|
||||||
- Update to 0.99; fixes #623607, helps work around #537430.
|
- Update to 0.99; fixes #623607, helps work around #537430.
|
||||||
- Sync Fedora license list with Wiki revision 1.80.
|
- Sync Fedora license list with Wiki revision 1.80.
|
||||||
|
Loading…
Reference in New Issue
Block a user