Subject: Re: mmap(), security and /dev/zero
To: Alan Barrett <apb@cequrux.com>
From: Bill Studenmund <wrstuden@netbsd.org>
List: tech-security
Date: 06/24/2004 12:19:51
--0eh6TmSyL6TZE2Uz
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Thu, Jun 24, 2004 at 10:58:54AM +0200, Alan Barrett wrote:
> How does the following compromise sound?
>=20
>         shlibs must be in files that have "r" permission.
>         shlibs must be on file systems that honour "x" permission
>                 (that is, were not mounted with the noexec option).

I think that sounds quite reasonable. And I don't think it'd be too hard=20
to implement.

Take care,

Bill

--0eh6TmSyL6TZE2Uz
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (NetBSD)

iD8DBQFA2ylXWz+3JHUci9cRAnCFAJ9AkMvEq3OqM1vg4+aX0vcKNUUQvgCfR6nj
gx/avvB+BLEeiXNbDsFB+rk=
=2prj
-----END PGP SIGNATURE-----

--0eh6TmSyL6TZE2Uz--