Re: [Mono-dev] Possible security issue with Mono's dllmaps in etc/config

2007-01-08 Thread Marek Habersack
On Mon, 8 Jan 2007 16:48:25 +0100, Paolo Molaro <[EMAIL PROTECTED]> scribbled: > On 01/08/07 Marek Habersack wrote: > > > > > os="!windows" /> > os="!windows"/> [snip] > In the future we'll allow listing multiple targets so if the dllimport > code can handle multiple versions, the dllmap code w

Re: [Mono-dev] Possible security issue with Mono's dllmaps in etc/config

2007-01-08 Thread Daniel Morgan
libmySQL.dll can be removed since Mono.Data.PostgreSqlClient has been replaced by fully managed ByteFX.Data a long time ago. As far as I'm concerned, it is up to the packager to know what the dllmaps should be. Or maybe configure.in foo can be added to detect what native libraries they actually h

Re: [Mono-dev] Possible security issue with Mono's dllmaps in etc/config

2007-01-08 Thread Paolo Molaro
On 01/08/07 Marek Habersack wrote: > > > > > we may encounter two issues. First (not security related, just usage > annoyance) is that on some Linux distributions the lib*.so file won't > exist unless there are devel packages installed for the library in > question. So unless the mono library m

Re: [Mono-dev] Possible security issue with Mono's dllmaps in etc/config

2007-01-08 Thread Sebastien Pouliot
On Mon, 2007-01-08 at 12:17 +0100, Marek Habersack wrote: > Hello everybody, Please send an email to [EMAIL PROTECTED] when/if you think you found an security related issue within Mono. http://www.mono-project.com/Vulnerabilities > Today while looking at the ODBC code in Mono, it occurred to me

[Mono-dev] Possible security issue with Mono's dllmaps in etc/config

2007-01-08 Thread Marek Habersack
Hello everybody, Today while looking at the ODBC code in Mono, it occurred to me that there might be a possible security problem with the way DLL maps are specified in the default $prefix/etc/mono/config file. Given entries like, we may encounter two issues. First (not security related, jus