[tor-bugs] #12103 [Tor bundles/installation]: Fully hardening firefox binary is broken since 3.5.3 on Linux
Tor Bug Tracker & Wiki
blackhole at torproject.org
Wed May 28 09:11:28 UTC 2014
#12103: Fully hardening firefox binary is broken since 3.5.3 on Linux
-------------------------------------+-------------------------------------
Reporter: gk | Owner: erinn
Type: defect | Status: new
Priority: normal | Milestone:
Component: Tor | Version:
bundles/installation | Keywords: tbb-security, tbb-
Resolution: | testcase
Actual Points: | Parent ID:
Points: |
-------------------------------------+-------------------------------------
Comment (by gk):
Replying to [comment:4 mikeperry]:
> In January, there was this fix to binutils: "Update bfd to properly
generate PT_GNU_RELRO segment for ld and objcopy. PRs 14207/16322/16323."
> http://gcc.gnu.org/ml/gcc/2014-01/msg00286.html
I tried 2.24.51.0.3 but still, objcopy is removing our RELRO. :(
> It seems like RedHat may have independently patched this or a related
issue in 2012: "Fix the creation of GNU_RELRO segments (#825736)"
> http://pkgs.org/centos-6/centos-
x86_64/binutils-2.20.51.0.2-5.36.el6.x86_64.rpm.html
Hrm... that bug is not visible for me, so not sure yet what they actually
fixed there.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/12103#comment:5>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list