buggy apparmor profile

Bug #1741581 reported by Seth Arnold
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
libreoffice (Ubuntu)
Fix Released
Medium
Olivier Tilloy

Bug Description

Nibaldo González has reported that the LibreOffice AppArmor profile has mistakes in it:

https://lists.ubuntu.com/archives/apparmor/2018-January/011418.html

> In this case, AppArmor grants write and read permissions to files with
> extension: '.#.txt', '.#All', '.the', '.format', '.#.xml', '.and',
> etc. Clearly, the profile must be fixed.

I've confirmed this via apparmor_parser -Qd output on a slightly modified
version of the source file:

$ apparmor_parser -Qd < foo | grep '#'
Warning from stdin (line 1): apparmor_parser: cannot use or update cache, disable, or force-complain via stdin
Mode: rwak: Name: ({/home//*,/root,/mnt,/media}/**.{[tT][xX][tT],#.txt,{,f,F}[oO][dDtT][tTsSpPbBgGfF],#All,the,open,document,format,[xX][mMsS][lL],#.xml,and,xsl,[pP][dD][fF],#.pdf,[uU][oO][fFtTsSpP],#Unified,office,format,{,x,X}[hH][tT][mM]{,l,L},#(x)htm(l),[jJ][pP][gG],[jJ][pP][eE][gG],[pP][nN][gG],[sS][vV][gG],[sS][vV][gG][zZ]99251,[tT][iI][fF],[tT][iI][fF][fF],[dD][oO][cCtT]{,x,X},[rR][tT][fF],[xX][lL][sSwWtT]{,x,X},[dD][iIbB][fF],#.dif,dbf,[cCtT][sS][vV],#.tsv,.csv,[sS][lL][kK],[pP][pP][tTsS]{,x,X},[pP][oO][tT]{,m,M},[sS][wW][fF],#Flash,[pP][sS][dD],#Photoshop,[mM][mM][lL]})

The comments on the variable assignment lines are carried through to the
policy.

Thanks

Revision history for this message
Seth Arnold (seth-arnold) wrote :

And a corresponding bug in the AppArmor project in case we wish to handle it there instead:

https://bugs.launchpad.net/apparmor/+bug/1741584

Revision history for this message
Olivier Tilloy (osomon) wrote :

Bug reported upstream, where the apparmor profiles are maintained: https://bugs.documentfoundation.org/show_bug.cgi?id=114915.

Changed in libreoffice (Ubuntu):
status: New → Confirmed
Changed in libreoffice-l10n (Ubuntu):
status: New → Confirmed
Changed in libreoffice (Ubuntu):
importance: Undecided → Medium
Changed in libreoffice-l10n (Ubuntu):
importance: Undecided → Medium
Olivier Tilloy (osomon)
Changed in libreoffice (Ubuntu):
assignee: nobody → Olivier Tilloy (osomon)
Changed in libreoffice-l10n (Ubuntu):
assignee: nobody → Olivier Tilloy (osomon)
Revision history for this message
Olivier Tilloy (osomon) wrote :
Olivier Tilloy (osomon)
Changed in libreoffice (Ubuntu):
assignee: Olivier Tilloy (osomon) → nobody
assignee: nobody → Olivier Tilloy (osomon)
status: Confirmed → Fix Released
no longer affects: libreoffice-l10n (Ubuntu)
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.