[Bug 1150557] New: AUDIT-1: tmpwatch: review of cron job file(s): /etc/cron.daily/tmpwatch
http://bugzilla.suse.com/show_bug.cgi?id=1150557 Bug ID: 1150557 Summary: AUDIT-1: tmpwatch: review of cron job file(s): /etc/cron.daily/tmpwatch Classification: openSUSE Product: openSUSE Tumbleweed Version: Current Hardware: Other OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: security-team@suse.de Reporter: matthias.gerstner@suse.com QA Contact: qa-bugs@suse.de CC: crrodriguez@opensuse.org, jsegitz@suse.com, malte.kraus@suse.com, matthias.gerstner@suse.com Blocks: 1150175 Found By: --- Blocker: --- +++ This bug was initially created as a clone of Bug #1150175 As discussed in the proactive security team we want to restrict the installation of cron job files in the future. To achieve this we first need to cover the currently existing packages that do this. tmpwatch installs a cron file in /etc/cron.daily/tmpwatch. It should be reviewed and whitelisted if all is well. -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.suse.com/show_bug.cgi?id=1150557 http://bugzilla.suse.com/show_bug.cgi?id=1150557#c1 --- Comment #1 from Cristian Rodríguez <crrodriguez@opensuse.org> --- the functionality of tmpwatch and more is provided by systemd-tmpfiles nowadays, you could also consider filling a drop request instead. -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.suse.com/show_bug.cgi?id=1150557 http://bugzilla.suse.com/show_bug.cgi?id=1150557#c2 --- Comment #2 from Matthias Gerstner <matthias.gerstner@suse.com> --- (In reply to crrodriguez@opensuse.org from comment #1)
the functionality of tmpwatch and more is provided by systemd-tmpfiles nowadays, you could also consider filling a drop request instead.
Thanks for the hint. We will consider it. A review makes sense anyways since the package is still shipped with older products. It will take some time until we manage to review all affected packages. -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.suse.com/show_bug.cgi?id=1150557 Malte Kraus <malte.kraus@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |IN_PROGRESS Assignee|security-team@suse.de |malte.kraus@suse.com -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.suse.com/show_bug.cgi?id=1150557 http://bugzilla.suse.com/show_bug.cgi?id=1150557#c3 Malte Kraus <malte.kraus@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|IN_PROGRESS |RESOLVED Resolution|--- |FIXED --- Comment #3 from Malte Kraus <malte.kraus@suse.com> --- The file-handling had me do a double-take, but it's safe after all. So this is fine. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com