Gentoo Archives: gentoo-hardened

From: Alex Efros <powerman@××××××××××××××××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] flash player plugin
Date: Fri, 30 Nov 2007 00:19:20
Message-Id: 20071130001726.GF4925@home.power
In Reply to: Re: [gentoo-hardened] flash player plugin by pageexec@freemail.hu
1 Hi!
2
3 On Fri, Nov 30, 2007 at 01:07:05AM +0200, pageexec@××××××××.hu wrote:
4 > thanks, you could uprade to a newer kernel eventually, .20 hasn't been
5 > supported for a long time and i fixed bugs since (unrelated to the current
6 > issue though).
7
8 Latests "stable" in portage now is 2.6.22-hardened-r8. I remember
9 discussion in this maillist about a week ago, with some hardened-related
10 bug reported in .22 and .23 kernels. I'm not sure is that fix already
11 included in .22-r8, that's why I doesn't upgrade yet. Do you know which
12 .22 or .23 ebuilds already contain your fix for that bug?
13
14 > thanks, i reproduced it with that site now. it seems that (probably)
15 > flash resorts to some runtime code generation, therefore chpax/paxctl
16 > -m on firefox and that opera wrapper is enough to get it to work, no
17 > need to disable non-exec pages altogether. not that it's a good solution
18
19 Yep, -m is what I tried first, but it won't help, so I tried another flags.
20
21
22 Just to be sure I understand you correctly, this issue is in flashplayer
23 plugin itself, and only Adobe can fix it (which is unlikely, I think).
24 So only possible choice is relax PaX for browsers :( or just don't use
25 flash applets which won't work without relaxing PaX. Correct?
26
27 --
28 WBR, Alex.
29 --
30 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] flash player plugin pageexec@××××××××.hu
Re: [gentoo-hardened] flash player plugin Ned Ludd <solar@g.o>