[apparmor] [Bug 1485850] [NEW] sshd profile missing some permissions (patch)

raf ubuntu at raf.org
Tue Aug 18 05:47:39 UTC 2015


Public bug reported:

The usr.sbin.sshd profile (as seen on debian8) is missing a few permissions:
Specifically:

  capability audit_write,
  /bin/zsh5 rUx,
  @{PROC}/@{pid}/loginuid r,
  /tmp/ssh-*[a-zA-Z0-9]*/ rw,

A patch is attached.

** Affects: apparmor-profiles
     Importance: Undecided
         Status: New

** Patch added: "Patch to add the missing permissions for sshd"
   https://bugs.launchpad.net/bugs/1485850/+attachment/4446430/+files/apparmor-profiles-usr.sbin.sshd.diff

-- 
You received this bug notification because you are a member of AppArmor
Developers, which is subscribed to AppArmor Profiles.
https://bugs.launchpad.net/bugs/1485850

Title:
  sshd profile missing some permissions (patch)

Status in AppArmor Profiles:
  New

Bug description:
  The usr.sbin.sshd profile (as seen on debian8) is missing a few permissions:
  Specifically:

    capability audit_write,
    /bin/zsh5 rUx,
    @{PROC}/@{pid}/loginuid r,
    /tmp/ssh-*[a-zA-Z0-9]*/ rw,

  A patch is attached.

To manage notifications about this bug go to:
https://bugs.launchpad.net/apparmor-profiles/+bug/1485850/+subscriptions



More information about the AppArmor mailing list