Fixed a local symlink attack where a rogue tss user could have gain ownership of arbitrary files in the system during installation/update of the trousers package. Reference: https://www.tenable.com/plugins/nessus/132338
Statement: The trousers versions as shipped as Red Hat Enterprise Linux 5, 6, 7 and 8 are not affected by this issue. The flaw resides on the post transaction scriptlet from the RPM package. This scriptlet doesn't exists on Red Hat Enterprise Linux RPM spec file.
Closing this flaw as NOTABUG as Red Hat's RPM packages for trousers doesn't execute the rpmsave data backup on post transaction scriptlet.