CVE-2026-33145: Default AllowAlternateShell to 'no'

This commit is contained in:
matt335672
2026-03-11 15:55:04 +00:00
parent 90275daf6d
commit 45f62bdedd
3 changed files with 5 additions and 4 deletions
+2 -1
View File
@@ -365,7 +365,8 @@ because the system is unable to check whether the user is an administrator.
.TP
\fBAllowAlternateShell\fR=\fI[true|false]\fR
If set to \fB0\fR, \fBfalse\fR or \fBno\fR, prevent usage of alternate shells by users.
Set to \fB1\fR, \fBtrue\fR or \fByes\fR, to allow alternate shells to
be specified by users.
.TP
\fBPassShellAsEnv\fR=\fI<name-of-environment-variable>\fR
+1 -1
View File
@@ -320,7 +320,7 @@ config_read_security(int file, struct config_security *sc,
sc->xauth_in_sysdir = 0;
sc->restrict_outbound_clipboard = 0;
sc->restrict_inbound_clipboard = 0;
sc->allow_alternate_shell = 1;
sc->allow_alternate_shell = 0;
sc->pass_shell_as_env = g_strdup("");
sc->xorg_no_new_privileges = 1;
sc->ts_users = g_strdup("");
+2 -2
View File
@@ -43,8 +43,8 @@ RestrictOutboundClipboard=none
; false: an alias of none
; yes: an alias of all
RestrictInboundClipboard=none
; Set to 'no' to prevent users from logging in with alternate shells
#AllowAlternateShell=true
; Set to 'yes' to allow users to log in with alternate shells
#AllowAlternateShell=no
; Normally, alternate shells (if permitted) are executed directly, as
; specified.
; If this is set, alternate shells are not actioned directly, but