Browse Source

r16689@tombo: nickm | 2008-07-03 11:03:14 -0400
Fix for bug 742: do not use O_CREAT on 2-option version of open(). Especially do not use it on /dev/null. Fix from Michael Scherer. Bugfix on 0.0.2pre19 (wow).


svn:r15626

Nick Mathewson 16 years ago
parent
commit
9d7a2d4eae
2 changed files with 4 additions and 2 deletions
  1. 3 0
      ChangeLog
  2. 1 2
      src/common/util.c

+ 3 - 0
ChangeLog

@@ -9,6 +9,9 @@ Changes in version 0.2.1.3-alpha - 2008-07-xx
       "root:wheel". Fixes bug 676, reported by Serge Koksharov.
     - Fix macro collision between OpenSSL 0.9.8h and Windows headers.
       Fixes bug 704; fix from Steven Murdoch.
+    - When opening /dev/null in finish_daemonize(), do not pass the
+      O_CREAT flag.  Fortify was complaining, and correctly so.  Fixes
+      bug 742; fix from Michael Scherer.  Bugfix on 0.0.2pre19.
 
 
 Changes in version 0.2.1.2-alpha - 2008-06-20

+ 1 - 2
src/common/util.c

@@ -3084,8 +3084,7 @@ finish_daemon(const char *desired_cwd)
     exit(1);
   }
 
-  nullfd = open("/dev/null",
-                O_CREAT | O_RDWR | O_APPEND);
+  nullfd = open("/dev/null", O_RDWR | O_APPEND);
   if (nullfd < 0) {
     log_err(LD_GENERAL,"/dev/null can't be opened. Exiting.");
     exit(1);