#
# Copyright (c) 2006, 2007, Oracle and/or its affiliates. All rights reserved.
#
# Permission is hereby granted, free of charge, to any person obtaining a
# copy of this software and associated documentation files (the "Software"),
# to deal in the Software without restriction, including without limitation
# the rights to use, copy, modify, merge, publish, distribute, sublicense,
# and/or sell copies of the Software, and to permit persons to whom the
# Software is furnished to do so, subject to the following conditions:
#
# The above copyright notice and this permission notice (including the next
# paragraph) shall be included in all copies or substantial portions of the
# Software.
#
# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
# IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
# FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
# THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
# LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
# FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER
# DEALINGS IN THE SOFTWARE.
#
#
Additional security checks for setuid programs that X.Org upstream doesn't
have yet.
diff -urp -x '*~' -x '*.orig' src/RdFToI.c src/RdFToI.c
--- src/RdFToI.c 2010-10-06 21:14:06.000000000 -0700
+++ src/RdFToI.c 2011-02-11 17:00:23.916602294 -0800
@@ -161,7 +161,15 @@ xpmPipeThrough(
goto err;
if ( 0 == pid )
{
- execlp(cmd, cmd, arg1, (char *)NULL);
+/* #ifdef SUNSOFT */
+ closefrom(3);
+ if (issetugid()) {
+ char commandpath[32] = "/usr/bin/";
+ strlcat(commandpath, cmd, sizeof(commandpath));
+ execl(commandpath, cmd, arg1, NULL);
+ } else
+/* #endif */
+ execlp(cmd, cmd, arg1, NULL);
perror(cmd);
goto err;
}