+2005-02-07 Bill Haneman <bill.haneman@sun.com>
+
+ * atk-bridge/bridge.c:
+ (atk_bridge_init): Added missing NULL in g_strconcat(),
+ also check for symlink before logging to
+ insecure directory. Thanks to meissner@suse.de.
+
2005-01-25 Padraig O'Briain <padraig.obriain@sun.com>
* tests/login-helper-server-test.c: Add return call to main
if (g_getenv ("ATK_BRIDGE_REDIRECT_LOG"))
{
- fname = g_strconcat ("/tmp/", g_get_prgname (), ".at-spi-log");
- freopen (fname, "w", stderr);
+ fname = g_strconcat ("/tmp/", g_get_prgname (), ".at-spi-log", NULL);
+ /* make sure we're not being redirected - security issue */
+ if (!g_file_test (fname, G_FILE_TEST_IS_SYMLINK))
+ freopen (fname, "w", stderr);
g_free (fname);
}