getaddrinfo security problem ?
Thorsten Kukuk
kukuk@suse.de
Wed May 23 00:24:00 GMT 2001
On Tue, May 22, Philip.Blundell@pobox.com wrote:
> >I would vote for the first option, removing
> >it completly like BSD has done this.
>
> That seems reasonable to me. As far as I know nobody uses Unix sockets in
> this way.
Ok, I removed the gaih_local code complete, AF_UNIX is now not longer
supported by getaddrinfo and we don't have the security problems
with sockets in /tmp.
I append the patch for getaddrinfo.c and the test program.
Thorsten
--
Thorsten Kukuk http://www.suse.de/~kukuk/ kukuk@suse.de
SuSE GmbH Deutschherrnstr. 15-19 D-90429 Nuernberg
--------------------------------------------------------------------
Key fingerprint = A368 676B 5E1B 3E46 CFCE 2D97 F8FD 4E23 56C6 FB4B
More information about the Libc-hacker
mailing list