xdm: Changes to 'master'

Matthieu Herrb herrb at kemper.freedesktop.org
Tue Oct 3 14:58:12 UTC 2017


 config/TakeConsole |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

New commits:
commit 50bd014ad8ed0b0af1e9e8130779acd0473a6899
Author: Matthieu Herrb <matthieu at herrb.eu>
Date:   Sun Oct 1 09:43:53 2017 +0200

    chown before chmod
    
    This prevents a malicious user logging out from calling
    chmod while still owning /dev/console and thus by-passing
    the '622' mode that is set here.
    
    Issue reported by Tim Chase. Thanks.
    
    Reviewed-by: Alan Coopersmith <alan.coopersmith at oracle.com>



More information about the xorg-commit mailing list