Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 91468 - iptables insecure file permission : informations leak
Summary: iptables insecure file permission : informations leak
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A4 [noglsa] jaervosz
Keywords:
: 109030 (view as bug list)
Depends on:
Blocks:
 
Reported: 2005-05-04 11:45 UTC by eromang
Modified: 2005-10-12 11:45 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description eromang 2005-05-04 11:45:42 UTC
Hello,

/var/lib/iptables/rules-saves is world readable

Give every local user firewall rules

Reproducible: Always
Steps to Reproduce:
1.
2.
3.

Actual Results:  
This file is world readable

Expected Results:  
This file should not be world readable
Comment 1 Robert Paskowitz (RETIRED) gentoo-dev 2005-05-04 18:23:44 UTC
Confirmed, and, I agree, file should not have o+r.
Comment 2 SpanKY gentoo-dev 2005-05-04 18:27:28 UTC
changed both init.d scripts and version bumped iptables-1.3.1-r4

the rules file is now chmod-ed to 0600
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-05-04 23:12:54 UTC
Reopening for GLSA decision. I vote NO.
Comment 4 eromang 2005-05-06 14:48:25 UTC
Hello,

Is the update do the chmod 600 alone, ore should the sysadmin do it manualy ?
If they should dot it manualy then a GLSA is needed, I think.

Regards.
Comment 5 SpanKY gentoo-dev 2005-05-06 14:52:23 UTC
i'd vote no too if i had a vote :P

the init.d script forces the permissions everytime you save
Comment 6 Romang 2005-05-06 14:55:41 UTC
So,

Then no need of GLSA :)

Regards.
Comment 7 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-05-06 15:08:45 UTC
Thx Romang for the notification.

Closing. Feel free to reopen if you disagree.
Comment 8 SpanKY gentoo-dev 2005-10-12 11:45:50 UTC
*** Bug 109030 has been marked as a duplicate of this bug. ***