This is the mail archive of the
binutils@sourceware.org
mailing list for the binutils project.
Re: Reporting of potential security issues in binutils ?
- From: Joseph Myers <joseph at codesourcery dot com>
- To: Tim Rühsen <tim dot ruehsen at gmx dot de>
- Cc: Binutils <binutils at sourceware dot org>
- Date: Fri, 8 Nov 2019 21:01:13 +0000
- Subject: Re: Reporting of potential security issues in binutils ?
- Ironport-sdr: vz+zCZ/7pZRfQNAhb5qAMNQPNDyvILdXOSzOaiXlR7i0o72HumiRrSOsoOyeF+5S0cKLEFG6AO 93dQEE71R07DE9lNlajYAn3Yc8yY0THoC620pu2tYI3zanSUdJy2PTAh03Q/j7ncUDp2MHKKpL Gi1GaXrtByGKM1GXjuuOxyBc7BwMYi1GzjgjN24cB+HIBYiH79Iego/vNSF8OoU2SLHtJjlPIg 69R+fKYfWyK42Z+A9293eqanm6d/4Oa2QW7CRZXOSOSNc4KpIwg3HNBp2DIxvU9Ck4l22kUrBa vA4=
- Ironport-sdr: bjpfFv+c8Ymw+i96bvgPt0R7u9HGdXc+zzo/qr+d0yVXC39bJeMfLKuVMkEOTXEwqZy72up6Lu DfzFuv8DWNrasCVd+r2xyYDX/67i4+Fu0QYfEms3AJ3H3VngSDhir1hK1G4mRWFmZk/ibgjeIS EN12uPKVqY19rYjrec6ysD0oK8NuGbXsaac2PBqZ1jAIlYcaSLmLUNSZ+zQ3KxIZVD0fHQ0Jca WOg5fcuZywqiIBldajuULW32jgli4VTqrXyMeBZXzLIZ7miwM9BmeAZeINXsoMXAJGOFIKnxGJ BEk=
- References: <360ff352-c196-264e-a987-6624c0469df5@gmx.de>
On Fri, 8 Nov 2019, Tim Rühsen wrote:
> Hi,
>
> what is the preferred way (or policy) to report security related issues
> like buffer overflows ? The bug tracker seems to have no 'confidential'
> flag. I just don't want to accidentally disclose such an issue.
binutils is not normally used in contexts that cross privilege boundaries,
and I think anyone using it for e.g. malware analysis will already know
that they need to sandbox the use of binutils programs for hostile inputs.
Thus, any security issue requiring hostile input files to exploit it seems
perfectly appropriate to report in public in Bugzilla. (I also think
allocating CVEs is fairly unhelpful for such issues, given the niche
nature of circumstances in which they are security problems and the likely
presence of very many similar issues that don't have CVEs.)
In the event of a security issue that doesn't need hostile input - e.g. a
linker bug that introduces security vulnerabilities in binaries linked
from realistic trusted inputs - more care might be needed.
--
Joseph S. Myers
joseph@codesourcery.com