Gentoo Archives: gentoo-dev

From: "Jason A. Donenfeld" <Jason@×××××.com>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Re: Can we get PIE on all SUID binaries by default, por favor?
Date: Tue, 24 Jan 2012 07:58:49
Message-Id: CAHmME9qZs-QjDOxnGM0oacw-0nadNmToJ-rnwRD0DNcA9i=gxg@mail.gmail.com
In Reply to: Re: [gentoo-dev] Re: Can we get PIE on all SUID binaries by default, por favor? by Zac Medico
1 On Mon, Jan 23, 2012 at 23:18, Zac Medico <zmedico@g.o> wrote:
2 >
3 > We've got experimental support for FEATURES=xattr since
4 > portage-2.2.0_alpha80. We can include that in the next portage-2.1.x
5 > release.
6 >
7
8 Awesome. If possible though, let's keep the no-SUID-ever discussion for
9 another thread, as xattr still raises the same point this thread is focused
10 on: if they're not PIE, they can be easily injected, and their "xattr"s
11 utilized for nefarious means.
12
13
14 > --
15 > Thanks,
16 > Zac
17 >
18 >