mirror of
https://git.FreeBSD.org/src.git
synced 2025-01-04 12:52:15 +00:00
MFS: Fix smrsh bypass bug.
This commit is contained in:
parent
1b5ce81c74
commit
509cae3754
Notes:
svn2git
2020-12-20 02:59:44 +00:00
svn path=/head/; revision=105016
@ -59,6 +59,8 @@ SM_IDSTR(id, "@(#)$Id: smrsh.c,v 8.58 2002/05/25 02:41:31 ca Exp $")
|
||||
#include <sm/limits.h>
|
||||
#include <sm/string.h>
|
||||
#include <sys/file.h>
|
||||
#include <sys/types.h>
|
||||
#include <sys/stat.h>
|
||||
#include <string.h>
|
||||
#include <ctype.h>
|
||||
#include <errno.h>
|
||||
@ -147,6 +149,7 @@ main(argc, argv)
|
||||
char *newenv[2];
|
||||
char pathbuf[1000];
|
||||
char specialbuf[32];
|
||||
struct stat st;
|
||||
|
||||
#ifndef DEBUG
|
||||
# ifndef LOG_MAIL
|
||||
@ -304,6 +307,38 @@ main(argc, argv)
|
||||
(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
|
||||
"Trying %s\n", cmdbuf);
|
||||
#endif /* DEBUG */
|
||||
if (stat(cmdbuf, &st) < 0)
|
||||
{
|
||||
/* can't stat it */
|
||||
(void) sm_io_fprintf(smioerr, SM_TIME_DEFAULT,
|
||||
"%s: %s not available for sendmail programs (stat failed)\n",
|
||||
prg, cmd);
|
||||
if (p != NULL)
|
||||
*p = ' ';
|
||||
#ifndef DEBUG
|
||||
syslog(LOG_CRIT, "uid %d: attempt to use %s (stat failed)",
|
||||
(int) getuid(), cmd);
|
||||
#endif /* ! DEBUG */
|
||||
exit(EX_UNAVAILABLE);
|
||||
}
|
||||
if (!S_ISREG(st.st_mode)
|
||||
#ifdef S_ISLNK
|
||||
&& !S_ISLNK(st.st_mode)
|
||||
#endif /* S_ISLNK */
|
||||
)
|
||||
{
|
||||
/* can't stat it */
|
||||
(void) sm_io_fprintf(smioerr, SM_TIME_DEFAULT,
|
||||
"%s: %s not available for sendmail programs (not a file)\n",
|
||||
prg, cmd);
|
||||
if (p != NULL)
|
||||
*p = ' ';
|
||||
#ifndef DEBUG
|
||||
syslog(LOG_CRIT, "uid %d: attempt to use %s (not a file)",
|
||||
(int) getuid(), cmd);
|
||||
#endif /* ! DEBUG */
|
||||
exit(EX_UNAVAILABLE);
|
||||
}
|
||||
if (access(cmdbuf, X_OK) < 0)
|
||||
{
|
||||
/* oops.... crack attack possiblity */
|
||||
|
Loading…
Reference in New Issue
Block a user