On 03/20/2015 02:06 AM, Daiki Ueno wrote: > I agree. Now that intl/ is almost[1] synchronized with gettext, what's > blocking this? I'm happy to include the patch in the upcoming gettext > release so non-glibc consumers also benefit from it.
The patch will use getauxval(AT_SECURE) or __libc_enable_secure (or issetuugid on other systems, but which I cannot test). It is not going to be very portable. -- Florian Weimer / Red Hat Product Security