Consider checking the real user id as opposed to the effective user id.
还没有人认领这个 Issue。
评估
- 难度
- 2/5
- 预计耗时
- 1-3 小时
- 新手友好度
- 38/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 停滞
- 技术栈
- c
调研方向
从 src/procmon.cpp 第 17 行开始,检查附近的 system() 调用和 UID 检查。确认当前的有效 UID 检查在 set-user-ID root 环境中的行为,然后更新该检查以满足 issue 所要求的真实 UID 行为,并验证此类环境会被拒绝。
由索引模型根据 Issue 内容生成。
描述
line 17 checks the effective uid, signalling it's ok to come from a set user id root environment. However, right under it there's a call to system(), which clearly signals this code has no business being used in such an environment.
- 主要语言
- C
- 星标
- 4.7k
- 派生
- 295
- 平均合并
- 4 分钟
- 30 天内合并 PR
- 8
环境准备
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
microsoft/ProcMon-for-Linux 的其他 Issue
-
难度 5/5 一周以上 新手友好度 25/100
microsoft/ProcMon-for-Linux#144 ·
-
难度 5/5 一周以上 新手友好度 20/100
microsoft/ProcMon-for-Linux#135 · 3 条评论 ·
-
难度 5/5 一周以上 新手友好度 25/100
microsoft/ProcMon-for-Linux#129 ·
-
难度 2/5 1-3 小时 新手友好度 35/100
microsoft/ProcMon-for-Linux#128 · 2 条评论 ·
-
难度 2/5 1-3 小时 新手友好度 25/100
microsoft/ProcMon-for-Linux#126 · 2 条评论 ·
查看 microsoft/ProcMon-for-Linux 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 68/100
trezor/trezor-firmware#7997 ·
维护者通常 2 天内回复
-
难度 2/5 1-3 小时 新手友好度 84/100
维护者通常 1 天内回复
-
area/ysql kind/bug priority/medium status/awaiting-triage
难度 2/5 1-3 小时 新手友好度 84/100
yugabyte/yugabyte-db#34415 ·
维护者通常 1 天内回复
-
难度 1/5 1-3 小时 新手友好度 78/100
KhronosGroup/OpenCL-Headers#318 ·
-
0.kind: build failure
难度 2/5 1-3 小时 新手友好度 73/100
维护者通常 1 天内回复