[Top][All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
movemail broken on MS-Windows
From: |
Eli Zaretskii |
Subject: |
movemail broken on MS-Windows |
Date: |
Fri, 02 Apr 2010 18:42:34 +0300 |
This change breaks movemail on Windows:
revno: 99810
committer: Chong Yidong <address@hidden>
branch nick: trunk
timestamp: Fri 2010-04-02 11:26:24 -0400
message:
Fix permissions handling (CVE-2010-0825).
* movemail.c (main): Check return values of setuid. Avoid
possibility of symlink attack when movemail is setgid mail
(CVE-2010-0825).
The reason is that Windows does not have setegid. (I'd suggest to add
a stub for it, just like we do with setuid.)
[Prev in Thread] |
Current Thread |
[Next in Thread] |
- movemail broken on MS-Windows,
Eli Zaretskii <=