require /etc/tcsd.conf to be owned by root:tss mode 640 for CVE-2020-24331

This commit is contained in:
Hugel 2020-09-29 19:57:09 +08:00
parent ba6ed4466a
commit 6ddffed868

View File

@ -1,6 +1,6 @@
Name: trousers Name: trousers
Version: 0.3.14 Version: 0.3.14
Release: 4 Release: 5
Summary: The open-source TCG Software Stack Summary: The open-source TCG Software Stack
License: BSD License: BSD
Url: http://trousers.sourceforge.net Url: http://trousers.sourceforge.net
@ -74,7 +74,7 @@ exit 0
%doc README ChangeLog AUTHORS %doc README ChangeLog AUTHORS
%license LICENSE %license LICENSE
%{_sbindir}/tcsd %{_sbindir}/tcsd
%config(noreplace) %attr(0600, tss, tss) %{_sysconfdir}/tcsd.conf %config(noreplace) %attr(0640, root, tss) %{_sysconfdir}/tcsd.conf
%attr(0644,root,root) %{_unitdir}/tcsd.service %attr(0644,root,root) %{_unitdir}/tcsd.service
%attr(0700, tss, tss) %{_localstatedir}/lib/tpm/ %attr(0700, tss, tss) %{_localstatedir}/lib/tpm/
%{_libdir}/libtspi.so.* %{_libdir}/libtspi.so.*
@ -93,6 +93,9 @@ exit 0
%changelog %changelog
* Tue Sep 29 2020 Hugel <gengqihu1@huawei.com> - 1.9.8-5
- require /etc/tcsd.conf to be owned by root:tss mode 640 for CVE-2020-24331
* Mon Sep 14 2020 wangchen <wangchen137@huawei.com> - 1.9.8-4 * Mon Sep 14 2020 wangchen <wangchen137@huawei.com> - 1.9.8-4
- Fix CVE-2020-24330 CVE-2020-24331 CVE-2020-24332 - Fix CVE-2020-24330 CVE-2020-24331 CVE-2020-24332