Fixes CVE-2011-4339 - world writeable PID file

Adds proper umask() before writing PID file.
This commit is contained in:
Zdenek Styblik 2012-01-24 13:26:56 +00:00
parent b6d2f7e302
commit 5ed7f6ac0a

View File

@ -746,6 +746,7 @@ ipmievd_main(struct ipmi_event_intf * eintf, int argc, char ** argv)
}
}
umask(022);
fp = ipmi_open_file_write(pidfile);
if (fp != NULL) {
fprintf(fp, "%d\n", (int)getpid());