[Xfce-bugs] [Bug 12282] [PATCH] xflock4: Do not override PATH with hardcoded value.

bugzilla-daemon at xfce.org bugzilla-daemon at xfce.org
Fri Jan 29 18:30:19 CET 2016


https://bugzilla.xfce.org/show_bug.cgi?id=12282

--- Comment #3 from Jarno Suni <8 at iki.fi> ---
(In reply to Jarno Suni from comment #2)

> I think it would be safer to check in xflock4 that the command is not
> user-writeable and is owned by root. (I have a shell function for that.)

Actually this is tricky. The command could be wrapped by e.g. "time ", "dash -c
" etc. so how do you find the final wrapped command?

-- 
You are receiving this mail because:
You are the assignee for the bug.


More information about the Xfce-bugs mailing list