OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: mmap(), security and /dev/zero

From: Curt Sampson (cjscynic.net)
Date: Wed Jun 23 2004 - 20:01:28 CDT


On Thu, 24 Jun 2004, Daniel Carosone wrote:

> No, it needs this change to work. Otherwise, potentially, a program
> executed from a r/o filesystem might be somehow tricked into loading
> shlibs from a writable path.

I don't quite understand this. Ought not any page in core backed by a
page on a noexec filesystem be marked non-executable, regardless of any
other circumstances?

cjs
--
Curt Sampson <cjscynic.net> +81 90 7737 2974 http://www.NetBSD.org
    Don't you know, in this new Dark Age, we're all light. --XTC