RFC: Adding a SECURITY.md document to the Binutils
Siddhesh Poyarekar
siddhesh@gotplt.org
Thu Apr 13 11:53:22 GMT 2023
On 2023-04-13 06:25, Richard Earnshaw wrote:
> So mention of networks reminds me that you don't always need privilege
> escalation to have a security compromise - simply transmitting a file to
> a third party, if that wasn't intended, would be enough.
None of the tools can guarantee this with untrusted input when executing
as a local user; this is why the last bit of sandboxing to analyze
untrusted input comes in.
> So I would suggest:
>
> A security bug is one that threatens the security of a system or
> network, or might compromise the security of data stored on it. In the
> context of GNU Binutils there are two ways in which such bugs might
> occur. In the first, the programs themselves might be tricked into a
> direct compromise of security. In the second, the tools might introduce
"Direct compromise of security" is essentially what we're trying to
define more strongly to prevent spurious CVE assignments.
> a vulnerability in the generated output that was not already present in
> the files used as input.
>
> Note: none of the programs in the GNU Binutils suite need elevated
> system privileges (eg setuid) to operate and we recommend that users do
> not use them from accounts where such privileges are automatically
> available.
We did have CVE-2021-20197, so it's not always setuid.
Thanks,
Sid
More information about the Binutils
mailing list