1 --- cyrus-sasl-1.5.27/lib/common.c~ Thu Oct 14 19:42:38 2004
2 +++ cyrus-sasl-1.5.27/lib/common.c Thu Oct 14 19:44:57 2004
7 - path = getenv(SASL_PATH_ENV_VAR);
8 + /* Honor external variable only in a safe environment */
9 + if (getuid() == geteuid() && getgid() == getegid())
10 + *path = getenv(SASL_PATH_ENV_VAR);
13 return _sasl_strdup(path, path_dest, NULL);