Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sat, 24 Jun 2017 16:14:42 +0200
From: Solar Designer <solar@...nwall.com>
To: oss-security@...ts.openwall.com
Subject: Re: Qualys Security Advisory - The Stack Clash

On Fri, Jun 23, 2017 at 08:02:36AM -0600, Kurt Seifried wrote:
> OpenBSD made changes to the then known qsort() issue, and implemented
> what was then thought to be the solution to the stack guard issue, the 1
> megabyte guard pages. Subsequent discussion (without OpenBSD present,
> due to them breaking the embargo) took place and as you know we ended up
> with some pretty significant changes to glibc (I don't know if OpenBSD
> has picked this group of fixes up or not).

I think Kurt's words "without OpenBSD present, due to them breaking the
embargo" are Kurt's (and maybe others') impression only (and maybe these
people's personal decision(s) not to inform OpenBSD going forward, as
Kurt mentioned he did help ping OpenBSD this time when Qualys wasn't
getting a response from them in early May).  No decision on the distros
list at large was made to either inform or not inform OpenBSD of further
issues.  As it happened, we did CC the discussion around Cron to Todd
(although like I said in my posting about Cron in here, there was no
point in having that minor issue embargoed in the first place).  The
glibc issues and fixes are most likely irrelevant to *BSD libc's - in
fact, we should have been more careful not to spam the full distros list
with them (I think some sub-threads correctly went to linux-distros
only, but some did not).

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.