[16/20] Core Update 157: Remove executable bit less ugly

Message ID 62f381bd-c870-107a-cd81-27cb283660bb@ipfire.org
State Accepted
Commit 4dfde0c08817e740eff09e8ffb59a2a419794204
Headers
Series Prevent "nobody" from escalating privileges by using writeable binaries as a vehicle |

Commit Message

Peter Müller May 17, 2021, 7:06 p.m. UTC
  Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
---
 config/rootfiles/core/157/update.sh | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)
  

Patch

diff --git a/config/rootfiles/core/157/update.sh b/config/rootfiles/core/157/update.sh
index e270ef338..d71c9688c 100644
--- a/config/rootfiles/core/157/update.sh
+++ b/config/rootfiles/core/157/update.sh
@@ -105,10 +105,12 @@  ldconfig
 
 # Fix file permissions changed
 chmod -s /usr/bin/gpg
-chmod -x /var/ipfire/fwhosts/icmp-types
+chmod -x \
+	/var/ipfire/fwhosts/icmp-types \
+	/var/ipfire/ovpn/ovpn-leases.db
+
 chown -R root:root /var/ipfire/urlfilter/bin
 chown -R root:root /var/ipfire/updatexlrator/bin
-chmod 600 /var/ipfire/ovpn/ovpn-leases.db
 
 # Delete scrubbed files
 rm -f \