Merge commit from fork

CVE-2026-33145: Default AllowAlternateShell to 'no'
This commit is contained in:
metalefty
2026-04-14 15:14:20 +09:00
committed by GitHub
3 changed files with 5 additions and 4 deletions
+2 -1
View File
@@ -365,7 +365,8 @@ because the system is unable to check whether the user is an administrator.
.TP .TP
\fBAllowAlternateShell\fR=\fI[true|false]\fR \fBAllowAlternateShell\fR=\fI[true|false]\fR
If set to \fB0\fR, \fBfalse\fR or \fBno\fR, prevent usage of alternate shells by users. Set to \fB1\fR, \fBtrue\fR or \fByes\fR, to allow alternate shells to
be specified by users.
.TP .TP
\fBPassShellAsEnv\fR=\fI<name-of-environment-variable>\fR \fBPassShellAsEnv\fR=\fI<name-of-environment-variable>\fR
+1 -1
View File
@@ -320,7 +320,7 @@ config_read_security(int file, struct config_security *sc,
sc->xauth_in_sysdir = 0; sc->xauth_in_sysdir = 0;
sc->restrict_outbound_clipboard = 0; sc->restrict_outbound_clipboard = 0;
sc->restrict_inbound_clipboard = 0; sc->restrict_inbound_clipboard = 0;
sc->allow_alternate_shell = 1; sc->allow_alternate_shell = 0;
sc->pass_shell_as_env = g_strdup(""); sc->pass_shell_as_env = g_strdup("");
sc->xorg_no_new_privileges = 1; sc->xorg_no_new_privileges = 1;
sc->ts_users = g_strdup(""); sc->ts_users = g_strdup("");
+2 -2
View File
@@ -43,8 +43,8 @@ RestrictOutboundClipboard=none
; false: an alias of none ; false: an alias of none
; yes: an alias of all ; yes: an alias of all
RestrictInboundClipboard=none RestrictInboundClipboard=none
; Set to 'no' to prevent users from logging in with alternate shells ; Set to 'yes' to allow users to log in with alternate shells
#AllowAlternateShell=true #AllowAlternateShell=no
; Normally, alternate shells (if permitted) are executed directly, as ; Normally, alternate shells (if permitted) are executed directly, as
; specified. ; specified.
; If this is set, alternate shells are not actioned directly, but ; If this is set, alternate shells are not actioned directly, but