Opened 13 years ago

Last modified 13 years ago

#160 closed bug

player_egid needs to be set for all SET_UID systems — at Version 1

Reported by: CJNyfalt Owned by:
Milestone: 3.0.8 Keywords: security pr2

Description (last modified by takkaria)

main.c: The player_egid variable needs to be set for all SET_UID code, not just HAVE_SETEGID. The relevant code should read like this:

#ifdef SET_UID

/* Get the user id (?) */
player_uid = getuid();

/* Save some info for later */
player_egid = getegid();

#endif /* SET_UID */

BTW, the comments could also use some cleanup.

Change History (1)

comment:1 Changed 13 years ago by takkaria

  • Description modified (diff)
  • Keywords security added; setgid player_egid bug removed
Note: See TracTickets for help on using tickets.