From 5653ddfeb61279df38e80ab18652afa68c964eb6 Mon Sep 17 00:00:00 2001 From: Jakub Filak Date: Wed, 30 Sep 2015 14:14:31 +0200 Subject: [PATCH] abrtd: switch owner of the dump location to 'root' Additional hardening suggested by Florian Weimer Related to CVE-2015-5287 Signed-off-by: Jakub Filak --- src/daemon/abrtd.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/daemon/abrtd.c b/src/daemon/abrtd.c index 0352eed..90a7163 100644 --- a/src/daemon/abrtd.c +++ b/src/daemon/abrtd.c @@ -195,7 +195,7 @@ static void sanitize_dump_dir_rights(void) * us with thousands of bogus or malicious dumps */ /* 07000 bits are setuid, setgit, and sticky, and they must be unset */ /* 00777 bits are usual "rwxrwxrwx" access rights */ - ensure_writable_dir(g_settings_dump_location, DEFAULT_DUMP_LOCATION_MODE, "abrt"); + ensure_writable_dir_group(g_settings_dump_location, DEFAULT_DUMP_LOCATION_MODE, "root", "abrt"); /* temp dir */ ensure_writable_dir(VAR_RUN"/abrt", 0755, "root"); } -- 2.6.3