• Adrian Bunk's avatar
    security/seclvl.c: fix time wrap (CVE-2005-4352) · e6169b53
    Adrian Bunk authored
    initlvl=2 in seclvl gives the guarantee
    "Cannot decrement the system time".
    
    But it was possible to set the time to the maximum unixtime value
    (19 Jan 2038) resulting in a wrap to the minimum value.
    
    This patch fixes this by disallowing setting the time to any date
    after 2030 with initlvl=2.
    Signed-off-by: default avatarAdrian Bunk <bunk@stusta.de>
    e6169b53
seclvl.c 17.4 KB