Package: coreutils
Version: 8.23-2
Severity: normal
File: /bin/df

Dear Maintainer,

coreutils is using hardeing build flags, which is great.  However, when I look 
at /bin/df I see that it uses a 
mixture of hardened and non-hardened functions:

$ objdump -R /bin/df | grep memcpy
08061030 R_386_JUMP_SLOT   memcpy
080610ac R_386_JUMP_SLOT   __memcpy_chk

This suggests that hardening does not cover all code paths.


-- System Information:
Debian Release: jessie/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: i386 (x86_64)
Foreign Architectures: amd64

Kernel: Linux 3.16-2-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages coreutils depends on:
ii  libacl1      2.2.52-2
ii  libattr1     1:2.4.47-2
ii  libc6        2.19-11
ii  libselinux1  2.3-2

coreutils recommends no packages.

coreutils suggests no packages.

-- no debconf information


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to