diff options
author | Matthieu Herrb <matthieu@cvs.openbsd.org> | 2011-10-18 14:58:37 +0000 |
---|---|---|
committer | Matthieu Herrb <matthieu@cvs.openbsd.org> | 2011-10-18 14:58:37 +0000 |
commit | 05e5b4254ea8853775c7514d8c575432f82219a1 (patch) | |
tree | 7687bfb27eca2ce32a1346448f6c8bbe7fdc3447 /xserver/include/dixfontstr.h | |
parent | d0704c63682975c2ee6237419fac92d3081e8947 (diff) |
Fix CVE-2011-4028: File disclosure vulnerability.
use O_NOFOLLOW to open the existing lock file, so symbolic links
aren't followed, thus avoid revealing if it point to an existing file.
Note that xserver on OpenBSD isn't affected by CVE-2011-4029.
Diffstat (limited to 'xserver/include/dixfontstr.h')
0 files changed, 0 insertions, 0 deletions