Bug 1421351 - /sbin/aide is not readable by non root
Summary: /sbin/aide is not readable by non root
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: aide
Version: 25
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Radovan Sroka
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-02-11 12:11 UTC by Michael S.
Modified: 2017-04-19 09:22 UTC (History)
3 users (show)

Fixed In Version: aide-0.16-2.fc24 aide-0.16-2.fc26 aide-0.16-2.fc25
Clone Of:
Environment:
Last Closed: 2017-04-18 16:48:51 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)
Fix permissions (1.26 KB, patch)
2017-02-11 12:14 UTC, Michael S.
no flags Details | Diff

Description Michael S. 2017-02-11 12:11:35 UTC
Description of problem:

aide is not readable nor executable by non root. This prevent someone from running it on his own home directory, or with a non root cronjob for more security (my goal being to verify a download server and the less I run as root, the better I feel, especially if the goal is to verify potentially untrusted input in case of compromise). 

Looking at history of the spec file, this was present in the CVS import in 2003, I can't find more information on why that's like this, the changelog do not mention anything about that specific part. 



Version-Release number of selected component (if applicable):
aide-0.16-0.2.rc1.fc25.x86_64 
that's also a issue on EPEL 7.

How reproducible:
each time

Steps to Reproduce:
1. dnf install aide
2. su - someuser
3. aide

Actual results:
$ aide
zsh: permission denied: aide


Expected results:
$ aide           
Cannot access config file: /etc/aide.conf: Permission denied
No config defined
Configuration error

Comment 1 Michael S. 2017-02-11 12:14:56 UTC
Created attachment 1249247 [details]
Fix permissions

Comment 2 Fedora Update System 2017-04-05 13:41:14 UTC
aide-0.16-2.fc26 has been submitted as an update to Fedora 26. https://bodhi.fedoraproject.org/updates/FEDORA-2017-3d891ea471

Comment 3 Fedora Update System 2017-04-05 13:41:42 UTC
aide-0.16-2.fc25 has been submitted as an update to Fedora 25. https://bodhi.fedoraproject.org/updates/FEDORA-2017-5162abbf03

Comment 4 Fedora Update System 2017-04-05 13:59:38 UTC
aide-0.16-2.fc24 has been submitted as an update to Fedora 24. https://bodhi.fedoraproject.org/updates/FEDORA-2017-a2d1c00128

Comment 5 Fedora Update System 2017-04-05 19:55:11 UTC
aide-0.16-2.fc25 has been pushed to the Fedora 25 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-5162abbf03

Comment 6 Fedora Update System 2017-04-05 21:56:13 UTC
aide-0.16-2.fc26 has been pushed to the Fedora 26 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-3d891ea471

Comment 7 Fedora Update System 2017-04-06 19:52:52 UTC
aide-0.16-2.fc24 has been pushed to the Fedora 24 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-a2d1c00128

Comment 8 Fedora Update System 2017-04-18 16:48:51 UTC
aide-0.16-2.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.

Comment 9 Fedora Update System 2017-04-18 19:57:49 UTC
aide-0.16-2.fc26 has been pushed to the Fedora 26 stable repository. If problems still persist, please make note of it in this bug report.

Comment 10 Fedora Update System 2017-04-19 09:22:49 UTC
aide-0.16-2.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.