OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Rob Mosher (rmosherLIGHTNING.NET)
Date: Wed Jan 03 2001 - 15:15:25 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    As pointed out by chris, GTK also accepts --gtk-module from the command
    line, at around line 238 in gtk-1.2.8, you can make sure euid == uid to
    prevent this from happenning. IE:

    if ((strcmp ("--gtk-module", (*argv)[i]) == 0 ||
    strncmp("--gtk-module=", (*argv)[i], 13) == 0) && geteuid() == getuid())

    --
    Rob Mosher
    Lead Programmer / Systems Engineer
    Lightning Internet Services, LLC