emacs-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

emacsclient socket ownership


From: Glenn Morris
Subject: emacsclient socket ownership
Date: Thu, 01 Nov 2018 12:43:43 -0400
User-agent: Gnus (www.gnus.org), GNU Emacs (www.gnu.org/software/emacs/)

Hi,

emacsclient defaults to predictable socket file names in /tmp:

/tmp/emacsUID/server

It checks if the socket is owned by the same user (function socket_status).
If the user is root, however, this check is ignored (master emacsclient
line 1370). Is this not a security issue? Any user can create a socket
/tmp/emacs0/server, and root emacsclient will use it.



reply via email to

[Prev in Thread] Current Thread [Next in Thread]