Subject: CVS commit: basesrc
To: None <source-changes@netbsd.org>
From: Christos Zoulas <christos@netbsd.org>
List: source-changes
Date: 11/29/2000 17:29:52
Module Name: basesrc
Committed By: christos
Date: Wed Nov 29 15:29:52 UTC 2000
Modified Files:
basesrc/usr.bin/calendar: calendar.c
Log Message:
Open only plain files [please someone add O_REG_ONLY]. Since /etc/daily
runs calendar -a, a malicious user can put a fifo in his home directory
to prevent calendar from completing. Many thanks to: dynamo@ime.net
To generate a diff of this commit:
cvs rdiff -r1.22 -r1.23 basesrc/usr.bin/calendar/calendar.c
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.