aboutsummaryrefslogtreecommitdiffstats
path: root/etc/disable-common.inc
diff options
context:
space:
mode:
authorLibravatar The Fox in the Shell <KellerFuchs@hashbang.sh>2017-01-10 00:13:07 +0100
committerLibravatar The Fox in the Shell <KellerFuchs@hashbang.sh>2017-01-10 00:13:07 +0100
commit0022b74ab59b807d982c06ea1a3d718356d9f147 (patch)
tree1feeac578d14b9acdb8e2c0057407036add90159 /etc/disable-common.inc
parentMerge pull request #1027 from reinerh/cve-references2 (diff)
downloadfirejail-0022b74ab59b807d982c06ea1a3d718356d9f147.tar.gz
firejail-0022b74ab59b807d982c06ea1a3d718356d9f147.tar.zst
firejail-0022b74ab59b807d982c06ea1a3d718356d9f147.zip
disable-common: Make mutt and msmtp's rc files R/O
Those allow arbitrary command executions through various mechanisms
Diffstat (limited to 'etc/disable-common.inc')
-rw-r--r--etc/disable-common.inc3
1 files changed, 3 insertions, 0 deletions
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index efe5c850d..3fdccf6d2 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -101,6 +101,9 @@ read-only ${HOME}/.caffrc
101read-only ${HOME}/.dotfiles 101read-only ${HOME}/.dotfiles
102read-only ${HOME}/dotfiles 102read-only ${HOME}/dotfiles
103read-only ${HOME}/.mailcap 103read-only ${HOME}/.mailcap
104read-only ${HOME}/.muttrc
105read-only ${HOME}/.mutt/muttrc
106read-only ${HOME}/.msmtprc
104read-only ${HOME}/.exrc 107read-only ${HOME}/.exrc
105read-only ${HOME}/_exrc 108read-only ${HOME}/_exrc
106read-only ${HOME}/.vimrc 109read-only ${HOME}/.vimrc