Re: RFC: Adding a SECURITY.md document to the Binutils
Alan Modra via Gdb <[email protected]>
| Newsgroups | gmane.comp.gdb.devel,gmane.comp.gnu.binutils |
|---|---|
| Message-ID | <[email protected]> |
On Thu, Apr 13, 2023 at 12:25:45AM -0400, Siddhesh Poyarekar wrote: > On 2023-04-12 23:51, Alan Modra wrote: > > On Wed, Apr 12, 2023 at 01:10:01PM -0400, Siddhesh Poyarekar wrote: > > > OK, then how about this for the first paragraph: > > > > > > ~~~ > > > A security bug is one that threatens the security of a system or network. > > > In the context of GNU Binutils, there are two ways in which a bug could have > > > security consequences. The primary method is when the tools introduce a > > > vulnerability in the output file that was not present in the input files > > > being processed. The other, albeit unlikely way is when a bug in the tools > > > results in a privilege boundary is crossed in either the tools themselves or > > > in the code they generate. > > > ~~~ > > > > I don't see that talking about privilege boundaries is particularly > > relevant. Consider this: > > > > It is trivially easy to craft an object file that when examined with > > objdump will read your ssh private keys. That's not a bug, it's a > > feature of thin archives. > > > > Now all you need is some means of delivering those private keys, and > > I'm sure there are plenty of buffer overflows in libbfd waiting to be > > exploited, especially with --enable-targets=all. > > That's not a crossing of privilege boundaries; I know. Ah, I see. You were saying that only the very narrow case of a privilege escalation will be considered a "security bug". Fair enough I suppose, but that's close to the much simpler and more easily understood: "binutils makes no claim to being secure, ergo there are no security bugs". -- Alan Modra Australia Development Lab, IBM