classpath-patches
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cp-patches] Patch: FYI: security buglet in ServerSocket


From: Tom Tromey
Subject: [cp-patches] Patch: FYI: security buglet in ServerSocket
Date: 22 Sep 2005 12:00:26 -0600

I'm checking this in.

I happened to notice that ServerSocket.accept calls the wrong
SecurityManager method.

Tom

Index: ChangeLog
from  Tom Tromey  <address@hidden>

        * java/net/ServerSocket.java (accept): Use correct security manager
        call.

Index: java/net/ServerSocket.java
===================================================================
RCS file: /cvsroot/classpath/classpath/java/net/ServerSocket.java,v
retrieving revision 1.41
diff -u -r1.41 ServerSocket.java
--- java/net/ServerSocket.java  2 Jul 2005 20:32:39 -0000       1.41
+++ java/net/ServerSocket.java  22 Sep 2005 18:02:51 -0000
@@ -316,7 +316,8 @@
   {
     SecurityManager sm = System.getSecurityManager();
     if (sm != null)
-      sm.checkListen(impl.getLocalPort());
+      sm.checkAccept(impl.getInetAddress().getHostAddress(),
+                     impl.getLocalPort());
 
     Socket socket = new Socket();
 




reply via email to

[Prev in Thread] Current Thread [Next in Thread]