emacs-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

movemail broken on MS-Windows


From: Eli Zaretskii
Subject: movemail broken on MS-Windows
Date: Fri, 02 Apr 2010 18:42:34 +0300

This change breaks movemail on Windows:

    revno: 99810
    committer: Chong Yidong <address@hidden>
    branch nick: trunk
    timestamp: Fri 2010-04-02 11:26:24 -0400
    message:
      Fix permissions handling (CVE-2010-0825).

      * movemail.c (main): Check return values of setuid.  Avoid
      possibility of symlink attack when movemail is setgid mail
      (CVE-2010-0825).

The reason is that Windows does not have setegid.  (I'd suggest to add
a stub for it, just like we do with setuid.)




reply via email to

[Prev in Thread] Current Thread [Next in Thread]