[15/20] Core Update 157: Apply changed permissions to /var/ipfire/ovpn/ovpn-leases.db

Message ID 0334d010-8b7d-7e4c-bf29-83f9bf12c229@ipfire.org
State Accepted
Commit 07bf7d14d66dac4192f9e5c8f3021e326bf6f82e
Headers
Series Prevent "nobody" from escalating privileges by using writeable binaries as a vehicle |

Commit Message

Peter Müller May 17, 2021, 7:06 p.m. UTC
  Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
---
 config/rootfiles/core/157/update.sh | 1 +
 1 file changed, 1 insertion(+)
  

Patch

diff --git a/config/rootfiles/core/157/update.sh b/config/rootfiles/core/157/update.sh
index c2fad638c..e270ef338 100644
--- a/config/rootfiles/core/157/update.sh
+++ b/config/rootfiles/core/157/update.sh
@@ -108,6 +108,7 @@  chmod -s /usr/bin/gpg
 chmod -x /var/ipfire/fwhosts/icmp-types
 chown -R root:root /var/ipfire/urlfilter/bin
 chown -R root:root /var/ipfire/updatexlrator/bin
+chmod 600 /var/ipfire/ovpn/ovpn-leases.db
 
 # Delete scrubbed files
 rm -f \