Menu

#7 Terminate after failed setuid/setgid

0.2
open
nobody
security (1)
2017-04-30
2017-04-30
linuxtardis
No

I think software should not execute user code when setuid() or setgid() failed. Checks for setenv() and execl() would be good too.

e4rat-collect: fix compiler warning setuid/setgid

Discussion


Log in to post a comment.