Blame SOURCES/0091-ccpp-do-not-read-data-from-root-directories.patch
|
|
a60cd7 |
From 4f2c1ddd3e3b81d2d5146b883115371f1cada9f9 Mon Sep 17 00:00:00 2001
|
|
|
a60cd7 |
From: Jakub Filak <jfilak@redhat.com>
|
|
|
a60cd7 |
Date: Wed, 15 Apr 2015 12:14:52 +0200
|
|
|
a60cd7 |
Subject: [ABRT PATCH] ccpp: do not read data from root directories
|
|
|
a60cd7 |
|
|
|
a60cd7 |
Users are allowed to modify /proc/[pid]/root to any directory by running
|
|
|
a60cd7 |
their own MOUNT namespace.
|
|
|
a60cd7 |
|
|
|
a60cd7 |
Related: #1211835
|
|
|
a60cd7 |
|
|
|
a60cd7 |
Signed-off-by: Jakub Filak <jfilak@redhat.com>
|
|
|
a60cd7 |
---
|
|
|
a60cd7 |
src/hooks/abrt-hook-ccpp.c | 2 +-
|
|
|
a60cd7 |
1 file changed, 1 insertion(+), 1 deletion(-)
|
|
|
a60cd7 |
|
|
|
a60cd7 |
diff --git a/src/hooks/abrt-hook-ccpp.c b/src/hooks/abrt-hook-ccpp.c
|
|
|
a60cd7 |
index 5694f84..0606519 100644
|
|
|
a60cd7 |
--- a/src/hooks/abrt-hook-ccpp.c
|
|
|
a60cd7 |
+++ b/src/hooks/abrt-hook-ccpp.c
|
|
|
a60cd7 |
@@ -678,7 +678,7 @@ int main(int argc, char** argv)
|
|
|
a60cd7 |
{
|
|
|
a60cd7 |
char *rootdir = get_rootdir(pid);
|
|
|
a60cd7 |
|
|
|
a60cd7 |
- dd_create_basic_files(dd, fsuid, (rootdir && strcmp(rootdir, "/") != 0) ? rootdir : NULL);
|
|
|
a60cd7 |
+ dd_create_basic_files(dd, fsuid, NULL);
|
|
|
a60cd7 |
|
|
|
a60cd7 |
char source_filename[sizeof("/proc/%lu/somewhat_long_name") + sizeof(long)*3];
|
|
|
a60cd7 |
int source_base_ofs = sprintf(source_filename, "/proc/%lu/smaps", (long)pid);
|
|
|
a60cd7 |
--
|
|
|
a60cd7 |
1.8.3.1
|
|
|
a60cd7 |
|