From d413204a32352258d8a94fc9d00e2abbe793d6d1 Mon Sep 17 00:00:00 2001 From: "Yann E. MORIN" Date: Thu, 1 Aug 2019 18:22:32 +0200 Subject: [PATCH] package/iputils: drop setuid on arping arping can be used for arp poisoning, so it should really not be setuid. Reported-by: Petr Vorel Signed-off-by: Yann E. MORIN Acked-by: Petr Vorel Signed-off-by: Peter Korsgaard --- package/iputils/iputils.mk | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package/iputils/iputils.mk b/package/iputils/iputils.mk index b28222138f..7482bbdca1 100644 --- a/package/iputils/iputils.mk +++ b/package/iputils/iputils.mk @@ -80,7 +80,7 @@ IPUTILS_POST_INSTALL_TARGET_HOOKS += IPUTILS_CREATE_PING6_SYMLINK # handle permissions ourselves IPUTILS_CONF_OPTS += -DNO_SETCAP_OR_SUID=true define IPUTILS_PERMISSIONS - /usr/sbin/arping f 4755 0 0 - - - - - + /usr/sbin/arping f 755 0 0 - - - - - /usr/bin/clockdiff f 4755 0 0 - - - - - /bin/ping f 4755 0 0 - - - - - /usr/bin/traceroute6 f 4755 0 0 - - - - - -- 2.30.2