Gentoo Archives: gentoo-hardened

From: "Tóth Attila" <atoth@××××××××××.hu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Re: Security notice regarding hardened-sources
Date: Fri, 17 Sep 2010 17:02:31
Message-Id: 1b59d6e1fb88fbb46e64a87c8db9961f.squirrel@atoth.sote.hu
In Reply to: Re: [gentoo-hardened] Re: Security notice regarding hardened-sources by "Anthony G. Basile"
1 Thanks for the feedback about the sources.
2 What about the toolchain? What are the gcc, binutils and glibc versions
3 supported? What versions of the toolchain components advised for the brave
4 folk?
5
6 Thx:
7 Dw.
8 --
9 dr Tóth Attila, Radiológus, 06-20-825-8057, 06-30-5962-962
10 Attila Toth MD, Radiologist, +36-20-825-8057, +36-30-5962-962
11
12 2010.Szeptember 17.(P) 02:21 időpontban Anthony G. Basile ezt írta:
13 > -----BEGIN PGP SIGNED MESSAGE-----
14 > Hash: SHA1
15 >
16 > On 09/16/2010 06:47 PM, 7v5w7go9ub0o wrote:
17 >> On 09/16/10 17:15, Anthony G. Basile wrote:
18 >> []
19 >>
20 >>>
21 >>>
22 >>> As a result, certain configurations of hardened-sources are also
23 >>> vulnerable. As a work around until I get the fix into the tree and
24 >>> fast track stabilization, keep the following in mind:
25 >>
26 >> []
27 >>
28 >> Thank you for this note, Anthony!
29 >>
30 >> 1. Will hardened-sources be distributed via the tree, or via an overlay?
31 >> (IIRC, I got 2.6.34-r5 via the overlay, then it disappeared)
32 >>
33 >> 2. Same question about gcc; will hardened gcc come to us via an overlay?
34 >> (I see an update to 4.4.4-r2; IIRC I got 4.4.4-r1 via overlay).
35 >>
36 >> TIA
37 >>
38 >
39 >
40 > The overlay should not be used for anything anymore. Its around only
41 > for reference. (Zorry and I may want to look back at stuff we did.)
42 >
43 > In about a day or so you should see hardened-sources-2.6.32-r18.ebuild
44 > and hardened-sources-2.6.34-r6.ebuild appear in portage. Use one of
45 > those two.
46 >
47 >
48 > - --
49 > Anthony G. Basile, Ph.D.
50 > Gentoo Developer
51 > -----BEGIN PGP SIGNATURE-----
52 > Version: GnuPG v2.0.16 (GNU/Linux)
53 > Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
54 >
55 > iEYEARECAAYFAkyStJIACgkQl5yvQNBFVTUnnACgg1lYVsSGM2k5SG6VSBeJTPOI
56 > hhIAn0WTyGjbplsXD3JavTuBP6Xf2N5D
57 > =08GV
58 > -----END PGP SIGNATURE-----
59 >