FreeBSD-EN-24:02.libutil

Status
Not open for further replies.
F

FreeBSD Security

Guest
When deciding to apply a target user's personal configuration file, setusetcontext() checks the real user ID of the process whereas it should instead check the effective user ID, which is the one affecting the process' privileges and consequently which settings it can change and to which values.
Continue reading...
 
Status
Not open for further replies.
Back
Top