Monday, February 27, 2023

Re: On the remaining syscall(2) or __syscall(2) use in ports

Stuart Henderson <stu@spacehopper.org> wrote:

> This port is broken; doesn't work with our Perl version. 4.79 needs
> a patch to avoid segfaults because we don't have fexecve() and with
> that fixed still doesn't work (same errors as 4.75).

I've looked into fexecve() numerous times and I just cannot for the life
of me see how to avoid it becoming a component of attack methodology.

The people who invented must be completely unaware of the dangerous
tooling this brings to the table.

OpenBSD will never have it.

No comments:

Post a Comment