diff options
author | 2002-10-09 03:58:48 +0000 | |
---|---|---|
committer | 2002-10-09 03:58:48 +0000 | |
commit | 7ab672c8c2adcebb3b82ece64aec9e4e9269f4bc (patch) | |
tree | 5bf46a4510fea6d085d70faccc992870b222d694 | |
parent | predicates are part of the grammar now; in non-root case, predicates are (diff) | |
download | wireguard-openbsd-7ab672c8c2adcebb3b82ece64aec9e4e9269f4bc.tar.xz wireguard-openbsd-7ab672c8c2adcebb3b82ece64aec9e4e9269f4bc.zip |
Patch from sendmail.org to fix potential smrsh bypass described
in http://www.sendmail.org/smrsh.adv.txt
-rw-r--r-- | gnu/usr.sbin/sendmail/smrsh/smrsh.c | 35 |
1 files changed, 35 insertions, 0 deletions
diff --git a/gnu/usr.sbin/sendmail/smrsh/smrsh.c b/gnu/usr.sbin/sendmail/smrsh/smrsh.c index b5e8e6eb079..36d80d6b254 100644 --- a/gnu/usr.sbin/sendmail/smrsh/smrsh.c +++ b/gnu/usr.sbin/sendmail/smrsh/smrsh.c @@ -57,6 +57,8 @@ SM_IDSTR(id, "@(#)$Sendmail: smrsh.c,v 8.58 2002/05/25 02:41:31 ca Exp $") #include <sm/limits.h> #include <sm/string.h> #include <sys/file.h> +#include <sys/types.h> +#include <sys/stat.h> #include <string.h> #include <ctype.h> #include <errno.h> @@ -145,6 +147,7 @@ main(argc, argv) char *newenv[2]; char pathbuf[1000]; char specialbuf[32]; + struct stat st; #ifndef DEBUG # ifndef LOG_MAIL @@ -302,6 +305,38 @@ main(argc, argv) (void) sm_io_fprintf(smioout, SM_TIME_DEFAULT, "Trying %s\n", cmdbuf); #endif /* DEBUG */ + if (stat(cmdbuf, &st) < 0) + { + /* can't stat it */ + (void) sm_io_fprintf(smioerr, SM_TIME_DEFAULT, + "%s: %s not available for sendmail programs (stat failed)\n", + prg, cmd); + if (p != NULL) + *p = ' '; +#ifndef DEBUG + syslog(LOG_CRIT, "uid %d: attempt to use %s (stat failed)", + (int) getuid(), cmd); +#endif /* ! DEBUG */ + exit(EX_UNAVAILABLE); + } + if (!S_ISREG(st.st_mode) +#ifdef S_ISLNK + && !S_ISLNK(st.st_mode) +#endif /* S_ISLNK */ + ) + { + /* can't stat it */ + (void) sm_io_fprintf(smioerr, SM_TIME_DEFAULT, + "%s: %s not available for sendmail programs (not a file)\n", + prg, cmd); + if (p != NULL) + *p = ' '; +#ifndef DEBUG + syslog(LOG_CRIT, "uid %d: attempt to use %s (not a file)", + (int) getuid(), cmd); +#endif /* ! DEBUG */ + exit(EX_UNAVAILABLE); + } if (access(cmdbuf, X_OK) < 0) { /* oops.... crack attack possiblity */ |