cccp
Steve Beattie
steve@wirex.net
Tue Apr 17 18:38:00 GMT 2001
On Wed, Apr 18, 2001 at 12:44:00AM +0200, Kai Henningsen wrote:
> It also makes it *very* dangerous to *compile* untrusted source. Do you
> really want to feature gcc on bugtraq and risks?
Erm, while I agree that the proposed feature does significantly increase
the risks involved, how many people do you really believe audit
makefiles (with all the random odd files they include) to verify that
nothing nasty is done in them?
It is already dangerous to compile untrusted sources, especially those
with as complex build processes as gcc or glibc has.
--
Steve Beattie Don't trust programmers?
<steve@wirex.net> Complete StackGuard distro at
http://immunix.org/~steve/ immunix.org
More information about the Gcc
mailing list