Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation or update. External Reference: https://bugzilla.suse.com/show_bug.cgi?id=1191890
Created quagga tracking bugs for this issue: Affects: fedora-all [bug 2025913]
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-44038