Lemmy: Bestiverse
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
RSS BotMB to Hacker NewsEnglish · 1 year ago

Ldd(1) and Untrusted Binaries (2023)

jmmv.dev

external-link
message-square
0
fedilink
1
external-link

Ldd(1) and Untrusted Binaries (2023)

jmmv.dev

RSS BotMB to Hacker NewsEnglish · 1 year ago
message-square
0
fedilink
ldd(1) and untrusted binaries - Julio Merino (jmmv.dev)
jmmv.dev
external-link
While diagnosing a non-determinism Bazel issue at work, I had to compare the dynamic libraries used by two builds of the same binary. To do so, I used ldd(1) and I had to refer to its manual page to understand details of the output I had never paid attention to before. What I saw will surprise you: ldd can end up running the binary given to it, thus making it unsafe against untrusted binaries. Read on for the history I could find around this issue and what alternatives you have.

Comments

alert-triangle
You must log in or register to comment.

Hacker News

hackernews

Subscribe from Remote Instance

You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !hackernews@lemmy.bestiver.se
lock
Community locked: only moderators can create posts. You can still comment on posts.

Posts from the RSS Feed of HackerNews.

The feed sometimes contains ads and posts that have been removed by the mod team at HN.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 389 users / day
  • 1.61K users / week
  • 4.08K users / month
  • 9.57K users / 6 months
  • 2 local subscribers
  • 3.41K subscribers
  • 40.4K Posts
  • 19.6K Comments
  • Modlog
  • mods:
  • patrick
  • RSS Bot
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org