3 ms·
Static linking is really bad for security and it's not used more often in mission critical applications.
by ex_amazon_sde 8y ago
Static linking is really bad for security and it's not used more often in mission critical applications.
- burfog 8y agoDynamic linking is also really bad for security. There exist whole classes of bugs that require it. Library substitution is a big problem. If an attacker can get a library into a place where the executable looks for libraries, the attacker gains control. Merely having the capability to load a dynamic library is an issue. Generally, this means it is possible to load code into the process. Library ABI mismatches can be security bugs. There can exist two pieces of software that can be installed and used separately without trouble, but which have security bugs when both installed. This happens for example when the second piece of software to be installed brings along an updated library that isn't fully compatible (even bug-for-bug) with the one that the other software came with.