NetBSD-Bugs archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: kern/42420: $ORIGIN undefined on NetBSD



The following reply was made to PR kern/42420; it has been noted by GNATS.

From: christos%zoulas.com@localhost (Christos Zoulas)
To: gnats-bugs%NetBSD.org@localhost, kern-bug-people%netbsd.org@localhost, 
        gnats-admin%netbsd.org@localhost, netbsd-bugs%netbsd.org@localhost, 
        austinenglish+netbsd%gmail.com@localhost
Cc: 
Subject: Re: kern/42420: $ORIGIN undefined on NetBSD
Date: Wed, 11 Jul 2012 14:02:52 -0400

 On Jul 11,  5:10pm, mm_lists%pulsar-zone.net@localhost (Matthew Mondor) wrote:
 -- Subject: Re: kern/42420: $ORIGIN undefined on NetBSD
 
 |  I didn't yet check the code, but of interest:
 |  
http://www.h-online.com/open/news/item/Root-privileges-through-vulnerability-in-GNU-C-loader-1110182.html
 |  
 |  We must be sure that like for LD_PRELOAD and LD_LIBRARY_PATH, ORIGIN be
 |  disabled for setuid and setgid binaries.
 
 It is indeed disabled.
 
 christos
 


Home | Main Index | Thread Index | Old Index