From: "Siddharth" <sdoshi@mvista.com>
To: openembedded-core@lists.openembedded.org
Subject: Re: [mickledore][PATCH] binutils: Fix CVE-2023-39128
Date: Mon, 11 Sep 2023 00:25:43 -0700 [thread overview]
Message-ID: <28187.1694417143207079753@lists.openembedded.org> (raw)
In-Reply-To: <20230908124109.70317-1-sanjanasanju1608@gmail.com>
[-- Attachment #1: Type: text/plain, Size: 545 bytes --]
Hi Sanjana,
Thank-you for this patch.
But, i feel this is not the right way to patch this vulnerability. No doubts the patch is released for binutils-gdb, but that is because the sources are merged.
However, in our systems, the command gdb comes from gdb package and not from bintuils-gdb.
Additional confirmation can also be obtained from bintuils configuration where we are disabling gdb from bintuils.
So even after patching the vulnerability will exists as it not patched in gdb and where it is patched, the gdb is diasbled.
[-- Attachment #2: Type: text/html, Size: 583 bytes --]
prev parent reply other threads:[~2023-09-11 7:25 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-09-08 12:41 [mickledore][PATCH] binutils: Fix CVE-2023-39128 Sanjana
2023-09-11 7:25 ` Siddharth [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=28187.1694417143207079753@lists.openembedded.org \
--to=sdoshi@mvista.com \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox