[07/20] Core Update 157: /var/ipfire/fwhosts/icmp-types does not have to be executable

Message ID e48ad179-b64a-40d6-8f3d-b3f88a989489@ipfire.org
State Accepted
Commit e621c85c71d274b47302f468eb3bb31e0b13d590
Headers
Series Prevent "nobody" from escalating privileges by using writeable binaries as a vehicle |

Commit Message

Peter Müller May 17, 2021, 7:03 p.m. UTC
  See commit 183ccaa5a5c95f4cb2b639360f3c1465567577e9.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
---
 config/rootfiles/core/157/update.sh | 1 +
 1 file changed, 1 insertion(+)
  

Patch

diff --git a/config/rootfiles/core/157/update.sh b/config/rootfiles/core/157/update.sh
index 8738a1e46..7ed02d690 100644
--- a/config/rootfiles/core/157/update.sh
+++ b/config/rootfiles/core/157/update.sh
@@ -105,6 +105,7 @@  ldconfig
 
 # Fix file permissions changed
 chmod -s /usr/bin/gpg
+chmod -x /var/ipfire/fwhosts/icmp-types
 
 # Delete scrubbed files
 rm -f \