Sign Up
Log In
Log In
or
Sign Up
Places
All Projects
Status Monitor
Collapse sidebar
SUSE:SLE-15-SP4:Update
libapparmor.29956
zgrep-profile-mr870.diff
Overview
Repositories
Revisions
Requests
Users
Attributes
Meta
File zgrep-profile-mr870.diff of Package libapparmor.29956
[Extended to include the fix from https://gitlab.com/apparmor/apparmor/-/merge_requests/873] From 3a3b49ccd93d00cbc373319b90c6acecdd6f45fa Mon Sep 17 00:00:00 2001 From: Christian Boltz <apparmor@cboltz.de> Date: Sun, 10 Apr 2022 15:03:08 +0200 Subject: [PATCH] Add zgrep and xzgrep profile This prevents exploiting https://www.openwall.com/lists/oss-security/2022/04/08/2 (code execution via "funny" filenames) --- profiles/apparmor.d/zgrep | 59 +++++++++++++++++++++++++++++++++++++++ 1 file changed, 59 insertions(+) create mode 100644 profiles/apparmor.d/zgrep Index: apparmor-3.0.4/profiles/apparmor.d/zgrep =================================================================== --- /dev/null +++ apparmor-3.0.4/profiles/apparmor.d/zgrep @@ -0,0 +1,62 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2021 Christian Boltz +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +abi <abi/3.0>, + +include <tunables/global> + +profile zgrep /usr/bin/{x,}zgrep { + include <abstractions/base> + include <abstractions/bash> + + /dev/tty rw, + /usr/bin/bash ix, + /usr/bin/bzip2 Cx -> helper, + /usr/bin/cat ix, + /usr/bin/expr ix, + /usr/bin/grep Cx -> helper, + /usr/bin/gzip Cx -> helper, + /usr/bin/mktemp ix, + /usr/bin/rm ix, + /usr/bin/sed Cx -> sed, + /usr/bin/xz Cx -> helper, + /usr/bin/xzgrep r, + /usr/bin/zgrep Cx -> helper, + /usr/bin/zstd Cx -> helper, + owner /tmp/zgrep* rw, + /usr/bin/zgrep r, + + include if exists <local/zgrep> + + profile helper { + include <abstractions/base> + + capability dac_override, + capability dac_read_search, + + /usr/bin/bash ix, + /usr/bin/bzip2 mr, + /usr/bin/grep mr, + /usr/bin/gzip mr, + /usr/bin/xz mr, + /usr/bin/zstd mr, + /{,**} r, + + } + + profile sed { + include <abstractions/base> + + /dev/tty rw, + /usr/bin/bash ix, + /usr/bin/sed mr, + + } +}
Locations
Projects
Search
Status Monitor
Help
OpenBuildService.org
Documentation
API Documentation
Code of Conduct
Contact
Support
@OBShq
Terms
openSUSE Build Service is sponsored by
The Open Build Service is an
openSUSE project
.
Sign Up
Log In
Places
Places
All Projects
Status Monitor