[Bug other/77409] CVE-2016-4973 Targets using libssp for SSP are missing -D_FORTIFY_SOURCE functionality
yselkowi at redhat dot com
gcc-bugzilla@gcc.gnu.org
Tue Aug 30 01:47:00 GMT 2016
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=77409
--- Comment #2 from Yaakov Selkowitz <yselkowi at redhat dot com> ---
(In reply to Andrew Pinski from comment #1)
> I don't think this is a security hole at all. In fact the security holes
> should be on the applications side rather than the library side.
The compiler is the cause and where this needs to be fixed first, therefore the
CVE was assigned to gcc.
More information about the Gcc-bugs
mailing list