diff options
author | Michal Srb <msrb@suse.com> | 2017-10-26 09:48:13 +0200 |
---|---|---|
committer | Matthieu Herrb <matthieu@herrb.eu> | 2017-11-25 11:45:41 +0100 |
commit | 7b377456f95d2ec3ead40f4fb74ea620191f88c8 (patch) | |
tree | 490711446aa5e24235d047a6dbebd44aba0084f6 /configure.ac | |
parent | d82dfe25491c599f650b2ad868772c3b8e6ba7bc (diff) |
Open files with O_NOFOLLOW. (CVE-2017-16611)
A non-privileged X client can instruct X server running under root to open any
file by creating own directory with "fonts.dir", "fonts.alias" or any font file
being a symbolic link to any other file in the system. X server will then open
it. This can be issue with special files such as /dev/watchdog.
Reviewed-by: Matthieu Herrb <matthieu@herrb.eu>
Diffstat (limited to 'configure.ac')
0 files changed, 0 insertions, 0 deletions