]> git.ozlabs.org Git - ppp.git/commitdiff
radattr: tighten permissions on radattr file to avoid information leakage. (#290)
authorJaco Kroon <jaco@uls.co.za>
Sat, 18 Sep 2021 02:02:54 +0000 (04:02 +0200)
committerGitHub <noreply@github.com>
Sat, 18 Sep 2021 02:02:54 +0000 (12:02 +1000)
Depending on the invoking process's umask it's possible that the radattr
file (which in certain cases can contain crytographic keys) be stored
with permissions such that world-read access is possible, resulting in
sensitive information being leaked to local users.

Signed-off-by: Jaco Kroon <jaco@uls.co.za>
Co-authored-by: Jaco Kroon <jaco@iewc.co.za>

No differences found