Go to:
Gentoo Home
Documentation
Forums
Lists
Bugs
Planet
Store
Wiki
Get Gentoo!
Gentoo's Bugzilla – Attachment 303711 Details for
Bug 405821
<dev-python/pastescript-2.0.2: Supplementary groups not dropped when started an application with "paster serve" as root (CVE-2012-0878)
Home
|
New
–
[Ex]
|
Browse
|
Search
|
Privacy Policy
|
[?]
|
Reports
|
Requests
|
Help
|
New Account
|
Log In
[x]
|
Forgot Password
Login:
[x]
[patch]
files/pastescript-1.7.5-usermod.patch
pastescript-1.7.5-usermod.patch (text/plain), 1.17 KB, created by
Ian Delaney (RETIRED)
on 2012-02-29 11:03:00 UTC
(
hide
)
Description:
files/pastescript-1.7.5-usermod.patch
Filename:
MIME Type:
Creator:
Ian Delaney (RETIRED)
Created:
2012-02-29 11:03:00 UTC
Size:
1.17 KB
patch
obsolete
># HG changeset patch ># User Clay Gerrard <clay.gerrard@gmail.com> ># Date 1328679050 21600 ># Branch setgroups ># Node ID a19e462769b4a5c675e25bb4dedbc0937deec8da ># Parent edb9ca5fdc1d47953896d131907eff810202089b >fix group permissions for paste.script.serve > >#diff -r edb9ca5fdc1d47953896d131907eff810202089b -r a19e462769b4a5c675e25bb4dedbc0937deec8da .hgignore >#--- a/.hgignore Mon Nov 07 10:11:44 2011 -0600 >#+++ b/.hgignore Tue Feb 07 23:30:50 2012 -0600 >#@@ -1,4 +1,5 @@ ># syntax: glob >#+*.pyc ># *.egg-info/ ># build/ ># dist/ >diff -r edb9ca5fdc1d47953896d131907eff810202089b -r a19e462769b4a5c675e25bb4dedbc0937deec8da paste/script/serve.py >--- a/paste/script/serve.py Mon Nov 07 10:11:44 2011 -0600 >+++ b/paste/script/serve.py Tue Feb 07 23:30:50 2012 -0600 >@@ -497,6 +497,11 @@ > if self.verbose > 0: > print 'Changing user to %s:%s (%s:%s)' % ( > user, group or '(unknown)', uid, gid) >+ if hasattr(os, 'initgroups'): >+ os.initgroups(user, gid) >+ else: >+ os.setgroups([e.gr_gid for e in grp.getgrall() >+ if user in e.gr_mem] + [gid]) > if gid: > os.setgid(gid) > if uid:
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Actions:
View
|
Diff
Attachments on
bug 405821
: 303711