** Changed in: firefox-3.5 (Ubuntu)
       Status: Fix Committed => Won't Fix

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to firefox in Ubuntu.
https://bugs.launchpad.net/bugs/507744

Title:
  build with PIE to gain remaining ASLR support

Status in “firefox” package in Ubuntu:
  Fix Released
Status in “firefox-3.5” package in Ubuntu:
  Won't Fix
Status in “xulrunner-1.9.1” package in Ubuntu:
  Fix Released

Bug description:
  Binary package hint: xulrunner-1.9.1

  The xulrunner stub used to build firefox is still non-relocatable, so
  a portion of the firefox memory image is predictable.  As part of the
  security team workitems, firefox should be built PIE.  There are no
  performance regressions, as tested by a javascript performance tool:

  http://dromaeo.com/?id=85736,85789,85802,85818

  First two are stock firefox, second two are PIE firefox.

  Attaching branches that implement PIE via hardening-wrapper.  I
  attempted to use hardening-includes, but something in the build does
  not correctly respect CFLAGS, CXXFLAGS, or LDFLAGS defined in the
  debian/rules file.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/507744/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to     : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to