oss-sec mailing list archives

Re: libdbus hardening


From: Solar Designer <solar () openwall com>
Date: Wed, 11 Jul 2012 17:31:28 +0400

On Wed, Jul 11, 2012 at 11:05:03AM +0200, Sebastian Krahmer wrote:
Ok. We are not in a hurry. I added the new patch to

https://bugzilla.novell.com/show_bug.cgi?id=697105

using __secure_getenv().

You could want to add a #warning after the #else (when __secure_getenv
is not detected by the configure script), although I'd prefer these
things to be fail-close (build failing if __secure_getenv is expected to
be present, but is not detected).  This is an issue with
security-related autoconf checks in general.

Alexander


Current thread: