Re: glibc hardening patch

2016-03-01 Thread Paul Wise
On Wed, Mar 2, 2016 at 3:34 AM, bancfc wrote: > Hi. After the recent glibc debacle I came across a patch to harden this > important library against common attack vectors. Please think about > reviewing and adding in Debian. The author warned there may be some package > breakage but nothing too se

Re: glibc hardening patch

2016-03-01 Thread bancfc
On 2016-03-01 20:06, Emilio Pozuelo Monfort wrote: You should file a bug against glibc if you want the glibc maintainers to consider that. Emilio Thanks for your suggestion. Feature request filed: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=816436

Re: glibc hardening patch

2016-03-01 Thread Emilio Pozuelo Monfort
On 01/03/16 20:34, ban...@openmailbox.org wrote: > Hi. After the recent glibc debacle I came across a patch to harden this > important library against common attack vectors. Please think about reviewing > and adding in Debian. The author warned there may be some package breakage but > nothing too s

glibc hardening patch

2016-03-01 Thread bancfc
Hi. After the recent glibc debacle I came across a patch to harden this important library against common attack vectors. Please think about reviewing and adding in Debian. The author warned there may be some package breakage but nothing too serious: http://seclists.org/oss-sec/2015/q1/604 I a