Re: RFC: Adding a SECURITY.md document to the Binutils

Alan Modra via Gdb <[email protected]>
Newsgroups gmane.comp.gdb.devel,gmane.comp.gnu.binutils
Message-ID <[email protected]>
On Wed, Apr 12, 2023 at 01:10:01PM -0400, Siddhesh Poyarekar wrote:
> OK, then how about this for the first paragraph:
> 
> ~~~
> A security bug is one that threatens the security of a system or network.
> In the context of GNU Binutils, there are two ways in which a bug could have
> security consequences. The primary method is when the tools introduce a
> vulnerability in the output file that was not present in the input files
> being processed.  The other, albeit unlikely way is when a bug in the tools
> results in a privilege boundary is crossed in either the tools themselves or
> in the code they generate.
> ~~~

I don't see that talking about privilege boundaries is particularly
relevant.  Consider this:

It is trivially easy to craft an object file that when examined with
objdump will read your ssh private keys.  That's not a bug, it's a
feature of thin archives.

Now all you need is some means of delivering those private keys, and
I'm sure there are plenty of buffer overflows in libbfd waiting to be
exploited, especially with --enable-targets=all.

-- 
Alan Modra
Australia Development Lab, IBM
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.