[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#720735: initramfs-tools: mkinitramfs uses ldd, which is insecure and generates core dumps



Control: retitle -1 initramfs-tools: Use static check for library dependencies instead of ldd
Control: severity -1 normal

On Sun, 2013-08-25 at 14:38 +0200, Vincent Lefevre wrote:
> On 2013-08-25 09:53:07 +0100, Ben Hutchings wrote:
> > No, this has a defined meaning in FHS:
> > 
> > http://www.pathname.com/fhs/pub/fhs-2.3.html#LIBLTQUALGTALTERNATEFORMATESSENTIAL
> 
> OK (both the French and English versions of the Wikipedia article
> didn't mention these directories... I've updated them now).
> 
> I still think that ldd should be avoided, though.

The core dump seems to have been due to a kernel bug, fixed in
3.14.15-1:

  * [amd64] Reject x32 executables if x32 ABI not supported

Ben.

-- 
Ben Hutchings
Logic doesn't apply to the real world. - Marvin Minsky

Attachment: signature.asc
Description: This is a digitally signed message part


Reply to: