[29966] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Portable OpenSSH: Dangerous AIX linker behavior (aixgcc.adv)

daemon@ATHENA.MIT.EDU (Valdis.Kletnieks@vt.edu)
Wed Apr 30 15:52:26 2003

Message-Id: <200304301809.h3UI9P5J005965@turing-police.cc.vt.edu>
To: Damien Miller <djm@mindrot.org>
In-Reply-To: Your message of "Wed, 30 Apr 2003 13:39:49 +1000."
             <Pine.LNX.4.44.0304301338010.8613-100000@mothra.mindrot.org> 
From: Valdis.Kletnieks@vt.edu
Mime-Version: 1.0
Content-Type: multipart/signed; boundary="==_Exmh_816324338P";
	 micalg=pgp-sha1; protocol="application/pgp-signature"
Content-Transfer-Encoding: 7bit
Date: Wed, 30 Apr 2003 14:09:25 -0400

--==_Exmh_816324338P
Content-Type: text/plain; charset=us-ascii

On Wed, 30 Apr 2003 13:39:49 +1000, Damien Miller <djm@mindrot.org>  said:
> 1. Systems affected:
> 
> 	Users of Portable OpenSSH prior to 3.6.1p2 on AIX are affected 
> 	if OpenSSH was compiled using a non-AIX compiler (e.g. gcc).

This is the same problem as I spotted in Sendmail 8.10.  Basically,
somewhere, linking is being done with "-L. -lfoo" or similar (in sendmail's
case, it was -L../otherdir type stuff).

Workaround/fix:  Link with "-bnolibpath -blibpath:/usr/local/lib:/usr/lib"
or similar.
-- 
				Valdis Kletnieks
				Computer Systems Senior Engineer
				Virginia Tech


--==_Exmh_816324338P
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
Comment: Exmh version 2.5 07/13/2001

iD8DBQE+sBFVcC3lWbTT17ARArHcAKCDu2hB3riPBiOAYAf+1AnQMmPvcgCeMCS4
vVg4msRDcdpI4ZhCMMwInjg=
=znrj
-----END PGP SIGNATURE-----

--==_Exmh_816324338P--

home help back first fref pref prev next nref lref last post