Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CALPTtNVBHYvoWcs_07X=toVFCiPB=+rgspEN4Kc5DMaPZv+ygg@mail.gmail.com>
Date: Fri, 5 Dec 2014 18:23:09 -0800
From: Reed Loden <reed@...dloden.com>
To: oss-security <oss-security@...ts.openwall.com>
Subject: Re: Offset2lib: bypassing full ASLR on 64bit Linux

On Fri, Dec 5, 2014 at 4:59 PM, Daniel Micay <danielmicay@...il.com> wrote:

>
> I don't really see how this would prevent Mozilla from shipping a
> browser with ASLR. The Tor browser has been shipping a fork of Firefox
> built as a position independent executable for ages. It doesn't impact
> users because they're either starting it via a .desktop file or the
> command-line.
>
> The support for desktop icons in Nautilus is deprecated / disabled by
> default with only a hidden dconf preference to enable it. If you really
> want to support the workflow of opening up the file manager, navigating
> to the binary and double-clicking it then using a wrapper script is a
> quite obvious solution.
>

Obviously, some users are running into it (
https://bugzilla.mozilla.org/show_bug.cgi?id=1076892), or it wouldn't have
had to be backed out.

~reed

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.