Gentoo Archives: gentoo-dev

From: Mike Frysinger <vapier@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Re: Can we get PIE on all SUID binaries by default, por favor?
Date: Tue, 24 Jan 2012 05:51:12
Message-Id: 201201240051.00474.vapier@gentoo.org
In Reply to: [gentoo-dev] Re: Can we get PIE on all SUID binaries by default, por favor? by "Diego Elio Pettenò"
1 On Monday 23 January 2012 14:37:40 Diego Elio Pettenò wrote:
2 > Il giorno lun, 23/01/2012 alle 20.26 +0100, Jason A. Donenfeld ha scritto:
3 > > When ASLR is turned on, the .text section of executables compiled with
4 > > PIE is given a randomized base address. When ASLR is off or when PIE
5 > > is not used, the base address is predictable, so it's easy to find
6 > > where to write into.
7 >
8 > Yup, I know that. I was just making sure that the actual prevention came
9 > from ASLR and not PIE by itself. Both because there is at least one
10 > sci-math package that cannot build with ASLR (randomize_va_space) turned
11 > on
12
13 emacs is known to crap itself when building with ASLR too, and the existing
14 workarounds (just like its own build system) tend to be fragile :(
15 -mike

Attachments

File name MIME type
signature.asc application/pgp-signature