4 ms·
An intermediate step is to run everything under AddressSanitizer, since it's fast enough for many cases. See, for example: https://blog.hboeck.de/archives/879
by masterleep 11y ago
An intermediate step is to run everything under AddressSanitizer, since it's fast enough for many cases. See, for example:
https://blog.hboeck.de/archives/879-Safer-use-of-C-code-running-Gentoo-with-Address-Sanitizer.html https://blog.hboeck.de/archives/879-Safer-use-of-C-code-runn...
- hannob 11y agoIt likely won't help. I excluded glibc from using ASAN to let this work. It is theoretically possible to use ASAN on glibc as well, but it's complicated and certainly not ready for any kind of production use. Also although this is my work, it's far from clear to me whether using ASAN in production really is a useful thing. Practically I'd rather suggest looking at the safestack and CFI features of clang for production use instead.
- yugr 11y agoBTW at least Clang's ASan is capable of detecting CVE-2015-7547 (in https://groups.google.com/forum/#!topic/address-sanitizer/ttPxNhTK9TU https://groups.google.com/forum/#!topic/address-sanitizer/tt...).