[PATCH] Allow %n in -D_FORTIFY_SOURCE=2 linux programs if /proc is not mounted
Ulrich Drepper
drepper@redhat.com
Wed Oct 20 10:22:00 GMT 2004
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Jakub Jelinek wrote:
> If /proc is not mounted, it is IMHO better to be less protected than
> fail on legitimate %n uses.
I'm not sure this is such a good idea. This can potentially affect only
a handful of programs, those running before /proc is mounted and those
used fater it is unmounted. If insight into t hose programs is hard
enough we should use your patch.
I worry about an exploit where a process running as root first run
umount for /proc to disable this and maybe other checks.
- --
â§ Ulrich Drepper â§ Red Hat, Inc. â§ 444 Castro St â§ Mountain View, CA â
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)
iD8DBQFBdjw52ijCOnn/RHQRAijkAJ4jexDj8zWdoVHU3d5lzibKB9TtTwCeNhRu
WvfPM+zC0fIySlUIOWYMpss=
=Opea
-----END PGP SIGNATURE-----
More information about the Libc-hacker
mailing list