2010-03-26 14:28:14 +00:00
|
|
|
--- a/svr-chansession.c
|
|
|
|
+++ b/svr-chansession.c
|
2015-09-02 11:48:57 +00:00
|
|
|
@@ -922,12 +922,12 @@ static void execchild(void *user_data) {
|
2005-03-06 03:53:29 +00:00
|
|
|
/* We can only change uid/gid as root ... */
|
|
|
|
if (getuid() == 0) {
|
|
|
|
|
2008-07-24 05:24:52 +00:00
|
|
|
- if ((setgid(ses.authstate.pw_gid) < 0) ||
|
|
|
|
+ if ((ses.authstate.pw_gid != 0) && ((setgid(ses.authstate.pw_gid) < 0) ||
|
|
|
|
(initgroups(ses.authstate.pw_name,
|
|
|
|
- ses.authstate.pw_gid) < 0)) {
|
|
|
|
+ ses.authstate.pw_gid) < 0))) {
|
2011-03-02 14:20:51 +00:00
|
|
|
dropbear_exit("Error changing user group");
|
2005-10-20 13:55:42 +00:00
|
|
|
}
|
2008-07-24 05:24:52 +00:00
|
|
|
- if (setuid(ses.authstate.pw_uid) < 0) {
|
|
|
|
+ if ((ses.authstate.pw_uid != 0) && (setuid(ses.authstate.pw_uid) < 0)) {
|
2011-03-02 14:20:51 +00:00
|
|
|
dropbear_exit("Error changing user");
|
2005-03-06 03:53:29 +00:00
|
|
|
}
|
|
|
|
} else {
|