eterm/src
Michael Jennings 883b2660af Wed May 14 16:09:04 2008 Michael Jennings (mej)
(Correct) fix for CVE-2008-1692.  Eterm no longer defaults to using
":0" for $DISPLAY due to the possibility that an attacker can create a
fake X server on a shared system, intercept the Eterm X connection,
and send fake keystrokes to the victim's Eterm to execute arbitrary
commands as that user.

The previous fix, while it did indeed correct the vulnerability, broke
the --display option.  The original fix from Bernhard Link was more
correct, albeit not quite on target.
----------------------------------------------------------------------


SVN revision: 34574
2008-05-14 23:16:54 +00:00
..
.cvsignore Initial import of Eterm 0.8.9 sources 1999-08-17 23:01:18 +00:00
.indent.pro Sun Apr 7 21:15:09 2002 Michael Jennings (mej) 2002-04-08 02:16:09 +00:00
Makefile.am Fri Aug 18 13:41:14 2006 Michael Jennings (mej) 2006-08-18 17:41:19 +00:00
actions.c Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
actions.h Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
buttons.c Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
buttons.h Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
command.c Wed May 14 12:42:51 2008 Michael Jennings (mej) 2008-05-14 19:49:22 +00:00
command.h Tue Aug 22 14:07:23 2006 Michael Jennings (mej) 2006-08-22 18:07:32 +00:00
defaultfont.c Fri Jul 23 12:21:25 2004 Michael Jennings (mej) 2004-07-23 16:23:06 +00:00
defaultfont.h Mon Apr 18 16:00:22 2005 Michael Jennings (mej) 2005-04-18 20:01:59 +00:00
draw.c Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
draw.h Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
e.c Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
e.h Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
encoding.c Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
encoding.h Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
eterm_debug.h Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
eterm_utmp.h Mon Feb 6 17:15:49 2006 Michael Jennings (mej) 2006-02-06 22:16:50 +00:00
events.c Wed May 14 14:54:16 2008 Michael Jennings (mej) 2008-05-14 21:54:45 +00:00
events.h Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
feature.h Fri Aug 18 13:41:14 2006 Michael Jennings (mej) 2006-08-18 17:41:19 +00:00
font.c Mon Feb 13 14:51:56 2006 Michael Jennings (mej) 2006-02-13 19:52:45 +00:00
font.h Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
gdb.scr Thu Aug 31 23:02:10 PDT 2000 Michael Jennings <mej@eterm.org> 2000-09-01 05:46:04 +00:00
grkelot.c Mon Apr 18 21:49:08 2005 Michael Jennings (mej) 2005-04-19 01:57:24 +00:00
grkelot.h Initial import of Eterm 0.8.9 sources 1999-08-17 23:01:18 +00:00
icon.h Mon Oct 27 21:39:29 2003 Michael Jennings (mej) 2003-10-28 02:42:53 +00:00
libscream.c Wed Oct 18 13:35:18 2006 Michael Jennings (mej) 2006-10-18 17:36:10 +00:00
main.c Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
menus.c Mon Feb 13 14:51:56 2006 Michael Jennings (mej) 2006-02-13 19:52:45 +00:00
menus.h Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
misc.c Mon Feb 13 14:51:56 2006 Michael Jennings (mej) 2006-02-13 19:52:45 +00:00
misc.h Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
mmx_cmod.S Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
options.c Wed May 14 14:54:16 2008 Michael Jennings (mej) 2008-05-14 21:54:45 +00:00
options.h Wed May 14 14:54:16 2008 Michael Jennings (mej) 2008-05-14 21:54:45 +00:00
pixmap.c Wed May 17 15:42:28 2006 Michael Jennings (mej) 2006-05-17 19:42:39 +00:00
pixmap.h Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
profile.h Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
scream.h * use clear-text commands to screen (^A:other i/o ^A^A etc.); this should 2005-05-12 13:09:28 +00:00
screamcfg.h Fri May 19 16:46:02 2006 Michael Jennings (mej) 2006-05-19 20:45:42 +00:00
screen.c Wed May 14 15:26:13 2008 Michael Jennings (mej) 2008-05-14 22:26:36 +00:00
screen.h Thu Sep 1 02:16:17 2005 Michael Jennings (mej) 2005-09-01 06:16:49 +00:00
script.c Mon Feb 13 14:51:56 2006 Michael Jennings (mej) 2006-02-13 19:52:45 +00:00
script.h Mon Feb 6 17:15:49 2006 Michael Jennings (mej) 2006-02-06 22:16:50 +00:00
scrollbar.c Mon Feb 13 14:51:56 2006 Michael Jennings (mej) 2006-02-13 19:52:45 +00:00
scrollbar.h Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
sse2_cmod.c Wed Jan 4 04:14:14 2006 Michael Jennings (mej) 2006-01-04 09:15:17 +00:00
startup.c Wed May 14 16:09:04 2008 Michael Jennings (mej) 2008-05-14 23:16:54 +00:00
startup.h Mon Oct 30 16:11:47 2006 Michael Jennings (mej) 2006-10-30 21:12:12 +00:00
system.c Fri May 19 16:46:02 2006 Michael Jennings (mej) 2006-05-19 20:45:42 +00:00
system.h Fri May 19 16:46:02 2006 Michael Jennings (mej) 2006-05-19 20:45:42 +00:00
term.c Wed May 14 14:54:16 2008 Michael Jennings (mej) 2008-05-14 21:54:45 +00:00
term.h Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
timer.c Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
timer.h Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00
utmp.c Mon Feb 13 14:51:56 2006 Michael Jennings (mej) 2006-02-13 19:52:45 +00:00
windows.c Mon Oct 30 16:11:47 2006 Michael Jennings (mej) 2006-10-30 21:12:12 +00:00
windows.h Wed Jan 4 04:22:13 2006 Michael Jennings (mej) 2006-01-04 09:22:41 +00:00