From owner-freebsd-security@FreeBSD.ORG Tue Aug 12 12:59:47 2003 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id D289137B401; Tue, 12 Aug 2003 12:59:47 -0700 (PDT) Received: from gw.celabo.org (gw.celabo.org [208.42.49.153]) by mx1.FreeBSD.org (Postfix) with ESMTP id 14C2343FA3; Tue, 12 Aug 2003 12:59:47 -0700 (PDT) (envelope-from nectar@celabo.org) Received: from madman.celabo.org (madman.celabo.org [10.0.1.111]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client CN "madman.celabo.org", Issuer "celabo.org CA" (verified OK)) by gw.celabo.org (Postfix) with ESMTP id 9109B5482B; Tue, 12 Aug 2003 14:59:46 -0500 (CDT) Received: by madman.celabo.org (Postfix, from userid 1001) id 20FBE6D461; Tue, 12 Aug 2003 14:59:46 -0500 (CDT) Date: Tue, 12 Aug 2003 14:59:46 -0500 From: "Jacques A. Vidrine" To: "Devon H. O'Dell" Message-ID: <20030812195946.GB51604@madman.celabo.org> Mail-Followup-To: "Jacques A. Vidrine" , "Devon H. O'Dell" , 'Jason Stone' , security@freebsd.org, kris@FreeBSD.org References: <20030812042912.V3417@walter> <006601c360c9$3c9cfc40$9f8d2ed5@internal> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <006601c360c9$3c9cfc40$9f8d2ed5@internal> X-Url: http://www.celabo.org/ User-Agent: Mutt/1.5.4i-ja.1 cc: 'Jason Stone' cc: kris@FreeBSD.org cc: security@freebsd.org Subject: Re: realpath(3) et al X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 12 Aug 2003 19:59:48 -0000 On Tue, Aug 12, 2003 at 01:59:51PM +0200, Devon H. O'Dell wrote: > In any case, IBM has a stack smashing protection patch for GCC 3.3 on > FreeBSD 4.8 available at > http://www.trl.ibm.com/projects/security/ssp/buildfreebsd.html (the > description page is at http://www.trl.ibm.com/projects/security/ssp/). It > currently works in the latest cvsupped source from 5.1 as well (I've built > and tested it). http://www.research.ibm.com/trl/projects/security/ssp/ has the latest. Yes, I'd like to see this in the base system as well. Our toolchain in 5.x is calming down a bit, maybe the timing is getting ripe. I thought Kris looked into this before, but I don't recall what might have ultimately stopped him from making the commits. cc:ing him in case he has insight to share. Cheers, -- Jacques Vidrine . NTT/Verio SME . FreeBSD UNIX . Heimdal nectar@celabo.org . jvidrine@verio.net . nectar@freebsd.org . nectar@kth.se