Gentoo Archives: gentoo-hardened

From: "Anthony G. Basile" <blueness@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Re: Security notice regarding hardened-sources
Date: Fri, 17 Sep 2010 00:22:28
Message-Id: 4C92B492.8010008@gentoo.org
In Reply to: [gentoo-hardened] Re: Security notice regarding hardened-sources by 7v5w7go9ub0o <7v5w7go9ub0o@gmail.com>
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 On 09/16/2010 06:47 PM, 7v5w7go9ub0o wrote:
5 > On 09/16/10 17:15, Anthony G. Basile wrote:
6 > []
7 >
8 >>
9 >>
10 >> As a result, certain configurations of hardened-sources are also
11 >> vulnerable. As a work around until I get the fix into the tree and
12 >> fast track stabilization, keep the following in mind:
13 >
14 > []
15 >
16 > Thank you for this note, Anthony!
17 >
18 > 1. Will hardened-sources be distributed via the tree, or via an overlay?
19 > (IIRC, I got 2.6.34-r5 via the overlay, then it disappeared)
20 >
21 > 2. Same question about gcc; will hardened gcc come to us via an overlay?
22 > (I see an update to 4.4.4-r2; IIRC I got 4.4.4-r1 via overlay).
23 >
24 > TIA
25 >
26
27
28 The overlay should not be used for anything anymore. Its around only
29 for reference. (Zorry and I may want to look back at stuff we did.)
30
31 In about a day or so you should see hardened-sources-2.6.32-r18.ebuild
32 and hardened-sources-2.6.34-r6.ebuild appear in portage. Use one of
33 those two.
34
35
36 - --
37 Anthony G. Basile, Ph.D.
38 Gentoo Developer
39 -----BEGIN PGP SIGNATURE-----
40 Version: GnuPG v2.0.16 (GNU/Linux)
41 Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
42
43 iEYEARECAAYFAkyStJIACgkQl5yvQNBFVTUnnACgg1lYVsSGM2k5SG6VSBeJTPOI
44 hhIAn0WTyGjbplsXD3JavTuBP6Xf2N5D
45 =08GV
46 -----END PGP SIGNATURE-----

Replies

Subject Author
Re: [gentoo-hardened] Re: Security notice regarding hardened-sources "Tóth Attila" <atoth@××××××××××.hu>