[Openstack-security] [Bug 1617343] [NEW] AIDE should not look at changes in /run

Major Hayden major at mhtx.net
Fri Aug 26 14:14:22 UTC 2016


Public bug reported:

AIDE shouldn't be wandering into /run since things there only live
temporarily.

---------------------------------------------------
Changed entries:
---------------------------------------------------

d =.... mc.. .. .: /etc/apparmor.d/libvirt
d =.... mc.. .. .: /etc/libvirt/qemu
d =.... mc.. .. .: /root
f >b... mc..C.. .: /root/.bash_history
f >.... mc..C.. .: /root/.ssh/known_hosts
f >b... mci.C.. .: /root/.viminfo
f =.... mci.C..  : /run/motd.dynamic
d >.... mc.. ..  : /run/shm
f =.... ....C..  : /run/shm/spice.29052
d =.... mc.. ..  : /run/systemd/sessions
d =.... mc.. ..  : /run/systemd/users
f =.... mci.C..  : /run/systemd/users/0
d >....    . ..  : /run/udev/data
d =.... mc.. ..  : /run/user

** Affects: openstack-ansible
     Importance: Low
     Assignee: Major Hayden (rackerhacker)
         Status: In Progress


** Tags: security

-- 
You received this bug notification because you are a member of OpenStack
Security, which is subscribed to OpenStack.
https://bugs.launchpad.net/bugs/1617343

Title:
  AIDE should not look at changes in /run

Status in openstack-ansible:
  In Progress

Bug description:
  AIDE shouldn't be wandering into /run since things there only live
  temporarily.

  ---------------------------------------------------
  Changed entries:
  ---------------------------------------------------

  d =.... mc.. .. .: /etc/apparmor.d/libvirt
  d =.... mc.. .. .: /etc/libvirt/qemu
  d =.... mc.. .. .: /root
  f >b... mc..C.. .: /root/.bash_history
  f >.... mc..C.. .: /root/.ssh/known_hosts
  f >b... mci.C.. .: /root/.viminfo
  f =.... mci.C..  : /run/motd.dynamic
  d >.... mc.. ..  : /run/shm
  f =.... ....C..  : /run/shm/spice.29052
  d =.... mc.. ..  : /run/systemd/sessions
  d =.... mc.. ..  : /run/systemd/users
  f =.... mci.C..  : /run/systemd/users/0
  d >....    . ..  : /run/udev/data
  d =.... mc.. ..  : /run/user

To manage notifications about this bug go to:
https://bugs.launchpad.net/openstack-ansible/+bug/1617343/+subscriptions




More information about the Openstack-security mailing list