Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 30 Jul 2012 10:59:59 +0200
From: Ludwig Nussel <ludwig.nussel@...e.de>
To: oss-security@...ts.openwall.com
Subject: Re: libdbus hardening

Florian Weimer wrote:
> On 07/17/2012 12:08 PM, Florian Weimer wrote:
> 
>> Note that GNU libc will likely change the name to secure_getenv.
>> Upstream does not want to document __secure_getenv as-is.
> 
> This will be part of glibc 2.17.  autoconf instructions are available here:
> 
> <http://sourceware.org/glibc/wiki/Tips_and_Tricks/secure_getenv>

Now the next step would be to make glibc automatically use secure_getenv
when running setuid root and require programs to explicitly call
insecure_getenv() or something like that :-)

cu
Ludwig

-- 
 (o_   Ludwig Nussel
 //\
 V_/_  http://www.suse.de/
SUSE LINUX Products GmbH, GF: Jeff Hawn, Jennifer Guild, Felix Imendörffer, HRB 16746 (AG Nürnberg) 

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.