This is the mail archive of the
gcc-bugs@gcc.gnu.org
mailing list for the GCC project.
[Bug other/77409] CVE-2016-4973 Targets using libssp for SSP are missing -D_FORTIFY_SOURCE functionality
- From: "pinskia at gcc dot gnu.org" <gcc-bugzilla at gcc dot gnu dot org>
- To: gcc-bugs at gcc dot gnu dot org
- Date: Tue, 30 Aug 2016 01:48:18 +0000
- Subject: [Bug other/77409] CVE-2016-4973 Targets using libssp for SSP are missing -D_FORTIFY_SOURCE functionality
- Auto-submitted: auto-generated
- References: <bug-77409-4@http.gcc.gnu.org/bugzilla/>
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=77409
--- Comment #4 from Andrew Pinski <pinskia at gcc dot gnu.org> ---
(In reply to Yaakov Selkowitz from comment #2)
> (In reply to Andrew Pinski from comment #1)
> > I don't think this is a security hole at all. In fact the security holes
> > should be on the applications side rather than the library side.
>
> The compiler is the cause and where this needs to be fixed first, therefore
> the CVE was assigned to gcc.
What I am trying to say is there is no security hole that this can cause, only
the badly written applications where the security holes are located.
Also this looks like it was by design.