Bug 706979
| Summary: | config file permissions are world readable | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 6 | Reporter: | Steve Grubb <sgrubb> |
| Component: | cronie | Assignee: | Marcela Mašláňová <mmaslano> |
| Status: | CLOSED ERRATA | QA Contact: | qe-baseos-daemons |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 6.1 | CC: | azelinka, jakub, jprokes, rbinkhor, rvokal, sradvan, syeghiay, vdanen |
| Target Milestone: | rc | Keywords: | EasyFix |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | cronie-1.4.4-9.el6 | Doc Type: | Bug Fix |
| Doc Text: |
Cause: File permissions on configuration file weren't too strict.
Consequence: Every user can read many configuration files of cron.
Fix: File permissions were changed.
Result: Only root can read the configuration files.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2013-11-21 22:22:57 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 782183, 960054 | ||
|
Description
Steve Grubb
2011-05-23 16:48:37 UTC
I can't be responsible for scripts in cron directories /etc/crond.*, because there are created by other applications or users. They are executable on purpose in some cases. Also please note -p option, which is used for crontabs in /var/spool/cron directory. Crontabs there should be according to your policy. <cite> crontab files have to be regular files or symlinks to regular files, they must not be executable or writable for anyone else but the owner. This requirement can be overridden by using the -p option on the crond command line. If inotify support is in use, changes in the symlinked crontabs are not automatically noticed by the cron daemon. </cite> Config files can be changed to 600 if they have higher permission. There is a script here that can be used for testing: http://people.redhat.com/sgrubb/files/stig-2011/stig-file-test.sh Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHBA-2013-1681.html |