[prev in list] [next in list] [prev in thread] [next in thread] 

List:       kde-commits
Subject:    branches/KDE/3.5/kdebase/kdm/backend
From:       Dirk Mueller <mueller () kde ! org>
Date:       2006-06-14 18:24:43
Message-ID: 1150309483.038195.8653.nullmailer () svn ! kde ! org
[Download RAW message or body]

SVN commit 551490 by mueller:

avoid ~/.dmrc symlink attack vulnerability (CVE-2006-2449)


 M  +0 -10     client.c  


--- branches/KDE/3.5/kdebase/kdm/backend/client.c #551489:551490
@@ -1537,16 +1537,6 @@
 
 	if (!StrApp( &fname, p->pw_dir, "/.dmrc", (char *)0 ))
 		return GE_Error;
-	if ((curdmrc = iniLoad( fname ))) {
-		free( fname );
-		return GE_Ok;
-	}
-
-	if (errno != EACCES) {
-		free( fname );
-		return GE_NoFile;
-	}
-
 	if (pipe( pfd ))
 		return GE_Error;
 	if ((pid = Fork()) < 0) {
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic