From 5229ddc5bce5b4dba8259f4057ca228112defd8e Mon Sep 17 00:00:00 2001 From: glitsj16 Date: Sun, 24 Feb 2019 22:16:09 +0000 Subject: Harden mediainfo.profile (#2467) --- etc/mediainfo.profile | 7 +++++++ 1 file changed, 7 insertions(+) (limited to 'etc') diff --git a/etc/mediainfo.profile b/etc/mediainfo.profile index 32a269fd3..6bb393376 100644 --- a/etc/mediainfo.profile +++ b/etc/mediainfo.profile @@ -14,7 +14,10 @@ include disable-interpreters.inc include disable-passwdmgr.inc include disable-programs.inc +apparmor caps.drop all +ipc-namespace +machine-id net none no3d nodbus @@ -36,3 +39,7 @@ private-cache private-dev private-etc alternatives private-tmp + +memory-deny-write-execute +noexec ${HOME} +noexec /tmp -- cgit v1.2.3-70-g09d2