[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: CVE against the fwknop package



[...]
The diff looks mostly ok, though checking for S_ISLNK from stat(2) seems
useless, and I'm not quite sure why the chmod is done *after* writing
the config file rather than upfront.

I have added the patches to fix the permission issues as done per upstream but keeping in mind no to change too much things on my own. I have also updated the patches to make it works against the rc2 but just a bit. For the client, the permissions should not be overwritten at the end of the function but rather set when created as you mentionned : I think you are right.

For the S_ISLNK, I have to check further.

I am going to check all that and try to make the 2.0.3 release build on MIPs.

Regards,

Franck



Reply to: