http://bugzilla.opensuse.org/show_bug.cgi?id=1191224
http://bugzilla.opensuse.org/show_bug.cgi?id=1191224#c1
Andreas Stieger changed:
What |Removed |Added
----------------------------------------------------------------------------
Status|NEW |CONFIRMED
CC| |Andreas.Stieger@gmx.de,
| |mardnh@gmx.de
Assignee|screening-team-bugs@suse.de |bwiedemann@suse.com
Summary|wireguard-tools: |VUL-0: wireguard-tools:
|/etc/wireguard permissions |/etc/wireguard
|should be 700 instead of |world-readable permissions
|755 |expose private keys
--- Comment #1 from Andreas Stieger ---
Looks like a CWE-276 in our package, from this superfluous line in the spec:
install -d %{buildroot}/%{_sysconfdir}/wireguard/
--
You are receiving this mail because:
You are on the CC list for the bug.