5 ms·
It's not cmake's job to limit the behaviour of programs written with it.
by saywatnow 9y ago
It's not cmake's job to limit the behaviour of programs written with it.
- al2o3cr 9y agoOTOH, allocating & using memory correctly so that a maliciously-crafted Makefile can't get elevated permissions is.
- pedrocr 9y agoA makefile can call whatever it wants so if you run a malicious one you're already hacked. There's nothing you can do with a cmake buffer overrun that you can't also do just by writing a normal cmake file to call out whichever malicious commands you want.
- throwaway613834 9y ago>> It's not cmake's job to limit the behaviour of programs written with it. > OTOH, allocating & using memory correctly so that a maliciously-crafted Makefile can't get elevated permissions is. https://en.wikipedia.org/wiki/Not_even_wrong https://en.wikipedia.org/wiki/Not_even_wrong
- martin_ky 9y agoYou are technically not wrong, of course, but if the attack vector got already to running Makefiles on your system, you should probably focus your effort to tighten security elsewhere.