4 ms·
But a "fix" in libc wouldn't help for the security risk because an attacker could still emit the system call directly. (Unless I misunderstood what the fix woul
by isomel 5y ago
But a "fix" in libc wouldn't help for the security risk because an attacker could still emit the system call directly.
(Unless I misunderstood what the fix would be)
- asveikau 5y agoAt first I imagine the libc killing the process if argv is empty. Otoh if you want libc to be possibly a little too clever, perhaps it could make an effort to try to discover a sensible value for argv[0] based on looking around /proc etc to find the path to the binary. That seems like way too much complexity and failure points for a few mostly inconsequential corner cases.
- thingsgoup 5y agoIf libc isn’t linked into the process to begin with then none of that matters.
- asveikau 5y agoMany languages that might want to bypass libc would also bounds check argv, so ... Maybe it doesn't matter in a few more senses than that ...