Gentoo Logo
Gentoo Spaceship




Note: Due to technical difficulties, the Archives are currently not up to date. GMANE provides an alternative service for most mailing lists.
c.f. bug 424647
List Archive: gentoo-dev
Navigation:
Lists: gentoo-dev: < Prev By Thread Next > < Prev By Date Next >
Headers:
To: "Jason A. Donenfeld" <Jason@...>
From: Diego Elio Pettenò <flameeyes@g.o>
Subject: Re: Can we get PIE on all SUID binaries by default, por favor?
Date: Mon, 23 Jan 2012 20:22:29 +0100
Hello Jason,

Il giorno lun, 23/01/2012 alle 20.08 +0100, Jason A. Donenfeld ha
scritto:

> So I recently published this: http://blog.zx2c4.com/749 , a local priv
> escalation.

I've seen the news :)

>  It doesn't work on Fedora because their /bin/su is compiled with
> -pie. (They don't compile gpasswd with -pie though, so they're still
> vulnerable.)

Is it because of PIE alone or ASLR? Just curious it doesn't make much
difference to me.

> In any case, what if we made it a policy in Gentoo to compile all SUID
> binaries with PIE, to prevent against any types of future attacks of
> this variety?

Here's the trick: it's hard to decide what to compile PIE and what not
because we generally don't split the build for the two. I guess a good
point here could be made to build _everything_ PIE, but it can be tricky
(at least hotot seem not to work on a PIE system).

It would be also a good idea to resume working on the file-based
capabilities, dropping suid altogether.

The main issue here: it's not just my call to make; toolchain and
council should probably chime in on this.

-- 
Diego Elio Pettenò <flameeyes@g.o>
Gentoo Linux
Attachment:
signature.asc (This is a digitally signed message part)
Replies:
Re: Can we get PIE on all SUID binaries by default, por favor?
-- Jason A. Donenfeld
References:
Can we get PIE on all SUID binaries by default, por favor?
-- Jason A. Donenfeld
Navigation:
Lists: gentoo-dev: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
Can we get PIE on all SUID binaries by default, por favor?
Next by thread:
Re: Can we get PIE on all SUID binaries by default, por favor?
Previous by date:
Can we get PIE on all SUID binaries by default, por favor?
Next by date:
Re: Can we get PIE on all SUID binaries by default, por favor?


Updated Jun 29, 2012

Summary: Archive of the gentoo-dev mailing list.

Donate to support our development efforts.

Copyright 2001-2013 Gentoo Foundation, Inc. Questions, Comments? Contact us.