build with PIE to gain remaining ASLR support

Bug #507744 reported by Kees Cook on 2010-01-15
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
firefox (Ubuntu)
Medium
Kees Cook
firefox-3.5 (Ubuntu)
Medium
Unassigned
xulrunner-1.9.1 (Ubuntu)
Medium
Unassigned

Bug Description

Binary package hint: xulrunner-1.9.1

The xulrunner stub used to build firefox is still non-relocatable, so a portion of the firefox memory image is predictable. As part of the security team workitems, firefox should be built PIE. There are no performance regressions, as tested by a javascript performance tool:

http://dromaeo.com/?id=85736,85789,85802,85818

First two are stock firefox, second two are PIE firefox.

Attaching branches that implement PIE via hardening-wrapper. I attempted to use hardening-includes, but something in the build does not correctly respect CFLAGS, CXXFLAGS, or LDFLAGS defined in the debian/rules file.

Kees Cook (kees) on 2010-01-15
Changed in firefox-3.5 (Ubuntu):
status: New → In Progress
importance: Undecided → Medium
Changed in xulrunner-1.9.1 (Ubuntu):
importance: Undecided → Medium
status: New → In Progress
Changed in firefox-3.5 (Ubuntu):
assignee: nobody → Kees Cook (kees)
Changed in xulrunner-1.9.1 (Ubuntu):
assignee: nobody → Kees Cook (kees)
Kees Cook (kees) on 2010-01-26
affects: firefox-3.5 (Ubuntu) → firefox (Ubuntu)
Changed in firefox (Ubuntu):
status: In Progress → Fix Released
Changed in xulrunner-1.9.1 (Ubuntu):
assignee: Kees Cook (kees) → nobody
status: In Progress → Fix Committed
Changed in firefox-3.5 (Ubuntu):
importance: Undecided → Medium
status: New → Fix Committed
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package xulrunner-1.9.1 - 1.9.1.8+build1+nobinonly-0ubuntu1

---------------
xulrunner-1.9.1 (1.9.1.8+build1+nobinonly-0ubuntu1) lucid; urgency=low

  * New upstream release v1.9.1.8 (FIREFOX_3_5_8_BUILD1)
    - see USN-896-1

  [ Kees Cook <email address hidden> ]
  * enable PIE build for increased security (LP: #507744)
    - update debian/rules
    - update debian/control
  * fix failure in build due to unrecognized line-end-escapes in Makefile
    - add debian/patches/fix-build-glitch.patch
    - update debian/patches/series

  [ Dmitrijs Ledkovs <email address hidden> ]
  * Merge dh_xulrunner fixes from Debian see http://bugs.debian.org/567746
  * Update documentation for dh_xulrunner
    - update debian/dh/dh_xulrunner.in
 -- Micah Gersten <email address hidden> Mon, 15 Feb 2010 10:54:56 -0600

Changed in xulrunner-1.9.1 (Ubuntu):
status: Fix Committed → Fix Released
Adolfo Jayme (fitojb) on 2014-02-14
Changed in firefox-3.5 (Ubuntu):
status: Fix Committed → Won't Fix
To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.