]> git.ipfire.org Git - thirdparty/binutils-gdb.git/commit
gdb: Update SECURITY.txt to mention extension scripts and internal errors
authorGuinevere Larsen <blarsen@redhat.com>
Thu, 13 Jun 2024 18:34:26 +0000 (15:34 -0300)
committerGuinevere Larsen <guinevere@redhat.com>
Wed, 30 Oct 2024 17:27:07 +0000 (14:27 -0300)
commitb02e6f38a6e4e064d2bb1b68d1f9d0b2c2afc517
tree879c7ff0ca706740f7cf65bd18dcf4315507746a
parent35d53ce6429a5e822aff29803956eb008775ef15
gdb: Update SECURITY.txt to mention extension scripts and internal errors

Given the recent CVE filed for GDB (CVE-2024-36699), I decided to update
the gdb/SECURITY.txt to be more explicit about some details. Specifically,
we now explicitly say that internal errors aren't security
vulnerabilities, and mention that users should review plugins before
running them, and under which conditions a plugin can cause a security
bug.

Reviewed-By: Tom Tromey <tom@tromey.com>
Approved-By: Luis Machado <luis.machado@arm.com>
Approved-By: Andrew Burgess <aburgess@redhat.com>
gdb/SECURITY.txt