[systemd-devel] About systemd call dbus session bus

Mantas Mikulėnas grawity at gmail.com
Fri Feb 6 04:11:58 PST 2015


On Fri, Feb 6, 2015 at 2:02 PM, Simon McVittie <
simon.mcvittie at collabora.co.uk> wrote:

> On 06/02/15 03:32, 张洋 wrote:
>
>> dbus-daemon --session --print-address --fork > /tmp/session_amgr
>>
>
> This is a security flaw (the search keywords to look for are "symlink
> attack").
>

True, although systemd sets fs.protected_symlinks=1 by default, which
should guard against that.

-- 
Mantas Mikulėnas <grawity at gmail.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.freedesktop.org/archives/systemd-devel/attachments/20150206/83f7daf9/attachment.html>


More information about the systemd-devel mailing list