Skip to content
Snippets Groups Projects
Unverified Commit 00be0af8 authored by Tobias Stoeckmann's avatar Tobias Stoeckmann Committed by GitHub
Browse files

pkexec: enforce absolute shell paths (#422)


Reading /etc/shells file directly has the effect that comments are
parsed as well. If a user sets environment variable SHELL to a value
which matches one of these comments, it is passed through pkexec.

The shadow tools would not allow such a login shell, so be as strict
as shadow when it comes to parsing /etc/shell.

Signed-off-by: default avatarTobias Stoeckmann <tobias@stoeckmann.org>
parent 70bd6cb9
No related branches found
No related tags found
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment