Fwd: [PATCH] Don't allow attackers to inject arbitrary data into stack through LD_DEBUG

Alex alexinbeijing@gmail.com
Mon Aug 10 07:04:00 GMT 2015


On Mon, Aug 10, 2015 at 1:01 AM, Andreas Schwab <schwab@linux-m68k.org> wrote:
> Alex Dowad <alexinbeijing@gmail.com> writes:
>
>> diff --git a/elf/rtld.c b/elf/rtld.c
>> index 6dcbabc..ee194a6 100644
>> --- a/elf/rtld.c
>> +++ b/elf/rtld.c
>> @@ -2408,6 +2408,8 @@ process_dl_debug (const char *dl_debug)
>>             char *copy = strndupa (dl_debug, len);
>>             _dl_error_printf ("\
>>  warning: debug option `%s' unknown; try LD_DEBUG=help\n", copy);
>
> Use %.*s instead.

Thanks for your reply. That would help to avoid potentially voluminous
output to the console, but doesn't fix the (potential) security hole
of copying an arbitrary, attacker-supplied string onto the stack. Do
you think there is any reason to copy the string at all? It seems like
it should be possible to just print it from whereever it originally
happened to be in memory.

Thanks, Alex



More information about the Libc-alpha mailing list