3 ms·
I noticed that Ubuntu only gave the patch for this vulnerability a "low" priority[1]. Furthermore, they state that "The default compiler options for affected re
by isaack 12y ago
I noticed that Ubuntu only gave the patch for this vulnerability a "low" priority[1]. Furthermore, they state that "The default compiler options for affected releases should reduce the vulnerability to a denial of service". Can someone enlighten me
1) What was the compiler flags used to harden this flaw?
2) Was the same compiler flags used to compile Debian packages?
Thanks,
[1] https://launchpad.net/ubuntu/trusty/+source/apt/1.0.1ubuntu2.4.1 https://launchpad.net/ubuntu/trusty/+source/apt/1.0.1ubuntu2...
[2] http://www.ubuntu.com/usn/usn-2353-1/ http://www.ubuntu.com/usn/usn-2353-1/
[3] http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-6273.html http://people.canonical.com/~ubuntu-security/cve/2014/CVE-20...