intelmqsetup changes the root directory ownership
kamil-certat opened this issue · comments
intelmqsetup
tries to fix ownership of related directories:
intelmq/intelmq/bin/intelmqsetup.py
Lines 172 to 176 in 7674949
However, the ROOT_DIR
can be set to /
:
Lines 18 to 20 in 7674949
This causes intelmqsetup
to take over the ownership of the root directory, what could open some security risk as well as break some system actions (e.g. systemd-tmpfiles
)
It should be noted that path == "lsb"
is only true if the user explicitly sets INTELMQ_PATHS_NO_OPT
, and only in installations from git/PyPI. Installations from packages are not affected, the affected code is not present there.