Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Set PATH to safe default #7

Closed
FooBarWidget opened this issue Mar 15, 2021 · 0 comments
Closed

Set PATH to safe default #7

FooBarWidget opened this issue Mar 15, 2021 · 0 comments

Comments

@FooBarWidget
Copy link
Owner

Matchhostfsowner executes external commands in order to perform certain operations. For example it executes "readlink". However, the user can abuse this by setting PATH to a location that contains arbitrary executables, that are then executed by matchhostfsowner with root privileges.

We should reset PATH to a safe default, restoring it only after having dropped privileges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant