Gentoo Archives: gentoo-hardened

From: William Robertson <wkr@×××××××.edu>
To: Alexander Gabert <pappy@g.o>
Cc: Darren Mutz <dhm@×××××××.edu>, gentoo-hardened@g.o, Christopher Kruegel <chris@×××××××.edu>, Fredrik Valeur <fredrik@×××××××.edu>
Subject: [gentoo-hardened] Re: http://www.cs.ucsb.edu/~wkr/projects/heap_protection/software.html
Date: Mon, 24 Nov 2003 05:37:20
Message-Id: 420AB8DA-1E40-11D8-8B1F-000A95675F0E@cs.ucsb.edu
In Reply to: [gentoo-hardened] http://www.cs.ucsb.edu/~wkr/projects/heap_protection/software.html by Alexander Gabert
1 On Nov 22, 2003, at 09:06, Alexander Gabert wrote:
2 > hi
3 >
4 > the glibc patch and the .rpm packages you have on your site are totally
5 > useless.
6
7 Alex,
8
9 Thanks for the bug reports. It turns out I screwed up the conversion
10 from enabling the protection with a hardcoded #define to enabling it
11 during configuration, but I believe the updated v1.3 patch has fixed
12 this. It also covers the seed buffer allocation bug. I'll be updating
13 the web page to reflect the new release shortly...
14
15 Let us know of any more issues you run into. It's great to have more
16 eyes on the code; the more auditing this stuff gets, the better I'll
17 feel about asking people to trust it.
18
19 --
20 William Robertson
21 Reliable Software Group, UC Santa Barbara
22 http://www.cs.ucsb.edu/~wkr/
23
24
25 --
26 gentoo-hardened@g.o mailing list