follow symlinks to find the true passwd file before updating.
authorpgf <pgf@69ca8d6d-28ef-0310-b511-8ec308f3f277>
Thu, 8 Nov 2007 01:12:38 +0000 (01:12 +0000)
committerpgf <pgf@69ca8d6d-28ef-0310-b511-8ec308f3f277>
Thu, 8 Nov 2007 01:12:38 +0000 (01:12 +0000)
git-svn-id: svn://busybox.net/trunk/busybox@20383 69ca8d6d-28ef-0310-b511-8ec308f3f277

libbb/update_passwd.c

index 388adf8..e99db40 100644 (file)
@@ -52,6 +52,10 @@ int update_passwd(const char *filename, const char *username,
        int cnt = 0;
        int ret = -1; /* failure */
 
+       filename = xmalloc_readlink_follow(filename);
+       if (filename == NULL)
+               return -1;
+
        check_selinux_update_passwd(username);
 
        /* New passwd file, "/etc/passwd+" for now */
@@ -143,6 +147,7 @@ int update_passwd(const char *filename, const char *username,
 
  free_mem:
        free(fnamesfx);
-       free((char*)username);
+       free((char *)filename);
+       free((char *)username);
        return ret;
 }