Remove obsolete world writeable /var/spool/samba

related: rhbz#1954531
This commit is contained in:
Andreas Schneider 2021-04-30 16:04:39 +02:00
parent 06c4d9cf0c
commit 05ca7887eb
2 changed files with 7 additions and 6 deletions

View File

@ -118,9 +118,9 @@
# This should be rc1 or nil
%global pre_release %nil
%global samba_release %{main_release}%{?dist}
%global samba_release %{main_release}
%if "x%{?pre_release}" != "x"
%global samba_release 0.%{main_release}.%{pre_release}%{?dist}
%global samba_release 0.%{main_release}.%{pre_release}
%endif
# This is a network daemon, do a hardened build
@ -145,7 +145,7 @@
Name: samba
Version: %{samba_version}
Release: %{samba_release}
Release: %{samba_release}%{?dist}
%if 0%{?rhel}
Epoch: 0
@ -1051,7 +1051,6 @@ install -d -m 0755 %{buildroot}/var/lib/samba/scripts
install -d -m 0755 %{buildroot}/var/lib/samba/sysvol
install -d -m 0755 %{buildroot}/var/lib/samba/winbindd_privileged
install -d -m 0755 %{buildroot}/var/log/samba/old
install -d -m 0755 %{buildroot}/var/spool/samba
install -d -m 0755 %{buildroot}/run/samba
install -d -m 0755 %{buildroot}/run/winbindd
install -d -m 0755 %{buildroot}/%{_libdir}/samba
@ -1493,7 +1492,6 @@ fi
%{_unitdir}/nmb.service
%{_unitdir}/smb.service
%attr(1777,root,root) %dir /var/spool/samba
%dir %{_sysconfdir}/openldap/schema
%config %{_sysconfdir}/openldap/schema/samba.schema
%config(noreplace) %{_sysconfdir}/pam.d/samba
@ -3878,6 +3876,9 @@ fi
%endif
%changelog
* Fri Apr 30 2021 Andreas Schneider <asn@redhat.com> - 4.14.4-2
- related: rhbz#1954531 - Remove obsolete /var/spool/samba
* Thu Apr 29 2021 Andreas Schneider <asn@redhat.com> - 4.14.4-1
- resolves: rhbz#1954531 - Update to Samba 4.14.4
- resolves: rhbz#1949446 - Fix CVE-2021-20254

View File

@ -281,7 +281,7 @@
[printers]
comment = All Printers
path = /var/spool/samba
path = /var/tmp
browseable = no
guest ok = no
writable = no