Skip to content

Conversation

@mpreisler
Copy link
Member

We only used to check paths with "bin" in them. That is potentially misleading because tampering with /usr/lib64 files can lead to a complete compromise of the system. We also weren't checking for documentation files. Attacker can mislead the user by changing manuals and man pages. See https://bugzilla.redhat.com/show_bug.cgi?id=1371555

@mpreisler mpreisler added the bugfix Fixes to reported bugs. label Mar 6, 2017
@mpreisler mpreisler added this to the 0.1.32 milestone Mar 6, 2017
@mpreisler
Copy link
Member Author

Broken a few files to verify this works:

image

@redhatrises
Copy link
Contributor

Ack.

@redhatrises redhatrises merged commit 1b9e6c2 into ComplianceAsCode:master Mar 7, 2017
@mpreisler mpreisler deleted the check_more_paths_rpm_hashes branch March 7, 2017 04:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Fixes to reported bugs.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants