[Neurodebian-upstream] False positives for lintian hardening tags

Sebastian Eichelbaum eichelbaum at informatik.uni-leipzig.de
Wed Jan 23 15:22:11 UTC 2013


Hi

Thank you for this hint. I've used hardening-check --verbose and it is indeed memset.

Thank you
Sebastian

On Wed, 23 Jan 2013, Yury V. Zaytsev wrote:

> Hi Sebastian,
> 
> On Wed, 2013-01-23 at 11:59 +0100, Sebastian Eichelbaum wrote:
> > 
> > The strange thing is that these lintian warnings get thrown only for
> > the plugin package. The main package containing our lib an executable
> > does not throw this warnings. Maybe you know a proper solution
> > (besides overriding these lintian tags) to get this fixed. Maybe one
> > of our other build flags overrides some hardening option?
> 
> Can you run the check in the verbose mode to see which specific
> functions remain unprotected?
> 
> Also, this is not the right forum for such bug reports, because none of
> the lintian developers are following this list.
> 
> You might wish to have a look at the following bug report by Ben where
> he's having a similar problem with vlc plugins:
> 
> http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=685299
> 
> I wonder if yours are false positives also due to memset and friends...
> 
> Z.
> 
> -- 
> Sincerely yours,
> Yury V. Zaytsev
> 
> 
> 
> _______________________________________________
> Neurodebian-upstream mailing list
> Neurodebian-upstream at lists.alioth.debian.org
> http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/neurodebian-upstream
> 

-- 
Dipl.-Inf. Sebastian Eichelbaum
Universität Leipzig
Institut für Informatik
Abteilung Bild- und Signalverarbeitung
PF 100920
D-04009 Leipzig



More information about the Neurodebian-upstream mailing list