Repository navigation
Security fix
Machine account files (*.macct) hold the Samba password hashes of an image's machine account. Since 7.4.5, linbo-torrent handed some of them to nobody: the copies in images/<image>/backups/ and below images/.incoming/, and briefly all of them on every run. The [linbo] rsync module serves /srv/linbo as nobody without login, so these files could be downloaded by anyone who can reach the server's rsync service.
Affected: linuxmuster-linbo7 7.4.5 to 7.4.18. The 4.3 series is not affected.
What to do: install this update. The package configure step makes every existing *.macct below /srv/linbo/images root:root with mode 600, so no manual step is needed. To check:
find /srv/linbo/images -name '*.macct' ! -user root
should print nothing.
If you cannot rule out that the files were downloaded, you can replace the exposed machine account password. Re-creating an image alone is not enough, because the image keeps the machine account password it was created with. Instead, have the Muster-Client rejoin the domain, reboot it and create the image right after that reboot. This is more effort, so weigh whether it is necessary for your installation.
What's Changed
- fix(linbo-torrent): never hand machine account files to nobody (#182, b760996) by @TomlDev
- fix(linbo-configure): make existing machine account files root-only on upgrade (#182, 03324a7)
Full Changelog: v7.4.18...v7.4.19