summaryrefslogtreecommitdiff
path: root/src/util
diff options
context:
space:
mode:
authorMichal Srb <msrb@suse.com>2017-10-26 09:48:13 +0200
committerMatthieu Herrb <matthieu@herrb.eu>2017-11-25 11:46:50 +0100
commit5ed8ac0e4f063825b8ecda48e9a111d3ce92e825 (patch)
tree0b836d558b8813796e5f54b6836d8adf6eb92039 /src/util
parentf581c2346d025d5b15926db9e58f254173fb58dc (diff)
Open files with O_NOFOLLOW. (CVE-2017-16611)
A non-privileged X client can instruct X server running under root to open any file by creating own directory with "fonts.dir", "fonts.alias" or any font file being a symbolic link to any other file in the system. X server will then open it. This can be issue with special files such as /dev/watchdog. Reviewed-by: Matthieu Herrb <matthieu@herrb.eu>
Diffstat (limited to 'src/util')
0 files changed, 0 insertions, 0 deletions