public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-dev] Can we get PIE on all SUID binaries by default, por favor?
@ 2012-01-23 19:08 Jason A. Donenfeld
  2012-01-23 19:22 ` [gentoo-dev] " Diego Elio Pettenò
  2012-01-24  5:58 ` [gentoo-dev] " Mike Frysinger
  0 siblings, 2 replies; 40+ messages in thread
From: Jason A. Donenfeld @ 2012-01-23 19:08 UTC (permalink / raw
  To: Diego E. Flameeyes; +Cc: gentoo-dev

[-- Attachment #1: Type: text/plain, Size: 405 bytes --]

Hi Diego,

So I recently published this: http://blog.zx2c4.com/749 , a local priv
escalation. It doesn't work on Fedora because their /bin/su is compiled
with -pie. (They don't compile gpasswd with -pie though, so they're still
vulnerable.) In any case, what if we made it a policy in Gentoo to compile *
all* SUID binaries with PIE, to prevent against any types of future attacks
of this variety?

Jason

[-- Attachment #2: Type: text/html, Size: 545 bytes --]

^ permalink raw reply	[flat|nested] 40+ messages in thread

end of thread, other threads:[~2012-02-01 20:08 UTC | newest]

Thread overview: 40+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-01-23 19:08 [gentoo-dev] Can we get PIE on all SUID binaries by default, por favor? Jason A. Donenfeld
2012-01-23 19:22 ` [gentoo-dev] " Diego Elio Pettenò
2012-01-23 19:26   ` Jason A. Donenfeld
2012-01-23 19:37     ` Diego Elio Pettenò
2012-01-23 19:40       ` Jason A. Donenfeld
2012-01-23 19:51         ` Mike Gilbert
2012-01-23 19:57           ` Jason A. Donenfeld
2012-01-23 20:00             ` Mike Gilbert
2012-01-23 20:09               ` Sven Vermeulen
2012-01-23 20:12               ` Francesco Riosa
2012-01-23 22:18                 ` Zac Medico
2012-01-24  7:57                   ` Jason A. Donenfeld
2012-01-24  5:56                 ` Mike Frysinger
2012-01-23 20:47               ` Agostino Sarubbo
2012-01-23 19:56         ` Diego Elio Pettenò
2012-01-23 20:48         ` Markos Chandras
2012-01-24  5:50       ` Mike Frysinger
2012-01-24  5:58 ` [gentoo-dev] " Mike Frysinger
2012-01-26 16:55   ` Jason A. Donenfeld
2012-01-27 19:02     ` Jason A. Donenfeld
2012-01-27 19:39       ` "Paweł Hajdan, Jr."
2012-01-27 19:45         ` Fabian Groffen
2012-01-27 20:13           ` "Paweł Hajdan, Jr."
2012-01-27 20:33             ` Rich Freeman
2012-01-27 21:05             ` Jason A. Donenfeld
2012-01-28  0:12               ` Mike Frysinger
2012-01-28  5:12                 ` Jason A. Donenfeld
2012-01-28 12:26                 ` Anthony G. Basile
2012-01-29 19:14                   ` Mike Frysinger
2012-02-01  0:58                     ` Anthony G. Basile
2012-02-01 17:33                       ` Matthew Thode
2012-02-01 20:08                       ` Mike Frysinger
2012-01-27 19:48         ` Mike Frysinger
2012-01-27 21:02         ` Jason A. Donenfeld
2012-01-28  0:01         ` Anthony G. Basile
2012-01-28  5:07           ` Jason A. Donenfeld
2012-01-29 19:14             ` Mike Frysinger
2012-01-27 19:42       ` Mike Frysinger
2012-01-27 19:43     ` Mike Frysinger
2012-01-27 21:04       ` Jason A. Donenfeld

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox