Bug#968277: mingw-w64: CVE-2018-5392 Fail to enable working ASLR on request

2020-08-12 Thread Stephen Kitt
Hi Petter, On Wed, 12 Aug 2020 12:45:32 +0200, Petter Reinholdtsen wrote: > [Stephen Kitt] > > Builds can supply the appropriate flags, but they need to do so > > consciously, it doesn’t make sense to enable them by default. > > Why not? I would expect it made sense to enable as many security

Bug#968277: mingw-w64: CVE-2018-5392 Fail to enable working ASLR on request

2020-08-12 Thread Petter Reinholdtsen
Control: -1 found 2.28-1 Dear Stephen, Thank you for the quick reply. :) [Stephen Kitt] > Builds can supply the appropriate flags, but they need to do so > consciously, it doesn’t make sense to enable them by default. Why not? I would expect it made sense to enable as many security defences

Bug#968277: mingw-w64: CVE-2018-5392 Fail to enable working ASLR on request

2020-08-12 Thread Stephen Kitt
Hi Petter, On Wed, 12 Aug 2020 11:53:50 +0200, Petter Reinholdtsen wrote: > According to > https://security-tracker.debian.org/tracker/CVE-2018-5392 >, the > issue is unsolved in Debian, thus I create this issue to track the > status. > > The problem at hand is that mingw-w64 fail to create bina

Bug#968277: mingw-w64: CVE-2018-5392 Fail to enable working ASLR on request

2020-08-12 Thread Petter Reinholdtsen
Package: mingw-w64 Version: 6.0.0-3 Severity: important Forwarded: https://sourceware.org/bugzilla/show_bug.cgi?id=19011 Tags: upstream patch According to https://security-tracker.debian.org/tracker/CVE-2018-5392 >, the issue is unsolved in Debian, thus I create this issue to track the status.