Bug 1835388

Summary: abrt-addon-ccpp causes failures during openscap scans on CCE-27119-7
Product: Red Hat Enterprise Linux 8 Reporter: Miroslav Suchý <msuchy>
Component: abrtAssignee: Michal Zidek <mzidek>
Status: CLOSED ERRATA QA Contact: Martin Kyral <mkyral>
Severity: low Docs Contact:
Priority: unspecified    
Version: 8.3CC: ggasparb, kbost, mhaicman, mkolbas, mkyral, mmarhefk, msuchy, mzidek, openscap-maint, qe-baseos-apps, rmullett, sgrubb
Target Milestone: rcFlags: pm-rhel: mirror+
Target Release: 8.0   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: 2.10.9-18.el8 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: 1796245 Environment:
Last Closed: 2020-11-04 01:31:18 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1796245    
Bug Blocks:    

Description Miroslav Suchý 2020-05-13 17:43:12 UTC
+++ This bug was initially created as a clone of Bug #1796245 +++

Description of problem:
The CCE-27119-7 openscap rule requires that all system executables have root ownership. There is a binary file provided by abrt-addon-ccpp that violates this, and is owned by abrt:abrt instead of root:root

-rwsr-sr-x. 1 abrt abrt 15432 Mar 20  2019 /usr/libexec/abrt-action-install-debuginfo-to-abrt-cache

Version-Release number of selected component (if applicable):
abrt-addon-ccpp-2.1.11-55.el7.x86_64

How reproducible:
Always

Steps to Reproduce:
1. Install abrt-addon-ccpp
2. Utilize openscap to scan the system

Actual results:
- The /usr/libexec/abrt-action-install-debuginfo-to-abrt-cache is owned by abrt:abrt

Expected results:
- The /usr/libexec/abrt-action-install-debuginfo-to-abrt-cache file should be owned by root:root


--- Additional comment from Miroslav Suchý on 2020-05-06 17:17:12 UTC ---

Upstream Pull Requests:
https://github.com/abrt/libreport/pull/631
https://github.com/abrt/abrt/pull/1485

Comment 9 errata-xmlrpc 2020-11-04 01:31:18 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (abrt bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2020:4435