Description of problem: The directory /etc/frr/ has the permissions frr:frr with 0755. As per (private) e-mail recommendation from the upstream security contact, this should be 0750 instead (like e.g. Debian has). This also would have partially avoided bug #1830805 and its possible information leak. Version-Release number of selected component (if applicable): frr-7.3-4.fc33 How reproducible: Always, see above and below. Actual results: /etc/frr/ with frr:frr and 0755 Expected results: /etc/frr/ with frr:frr and 0750 Additional info: Upstream mentioned that there will be a note in the future in the docs, too.
I agree that 0755 is not good here. I think that 644 or 640 might be much better suited for these config files.
Yes, but the point here is not only about the (partially dynamically generated) configuration files, but also about the /etc/frr/ directory itself.
FEDORA-2020-116a61bd59 has been submitted as an update to Fedora 32. https://bodhi.fedoraproject.org/updates/FEDORA-2020-116a61bd59
FEDORA-2020-efc4892faa has been pushed to the Fedora 31 testing repository. In short time you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2020-efc4892faa` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2020-efc4892faa See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2020-116a61bd59 has been pushed to the Fedora 32 testing repository. In short time you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2020-116a61bd59` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2020-116a61bd59 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2020-116a61bd59 has been pushed to the Fedora 32 stable repository. If problem still persists, please make note of it in this bug report.
FEDORA-2020-efc4892faa has been pushed to the Fedora 31 stable repository. If problem still persists, please make note of it in this bug report.