Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

facedetection包含的libmnnfacedetection.so存在编译选项相关安全风险,请关注解决 #54

Open
Simon-Good opened this issue Jul 27, 2021 · 1 comment

Comments

@Simon-Good
Copy link

facedetection-0.0.5.aar中的resources\jni\arm64-v8a\libmnnfacedetection.so,没有使用-fstack-protector-all或-fstack-protector-strong编译选项。可能导致缓冲区溢出攻击漏洞,导致应用程序被恶意劫持或崩溃。
按编译器不同:
1.GCC4.9版本及以上可使用-fstack-protector-strong进行加固
2.GCC4.9版本以下可使用-fstack-protector-all进行加固

请facedetection提供经过安全的编译选项加固后的so,谢谢

参考链接:https://android-developers.googleblog.com/2016/07/protecting-android-with-more-linux.html

@Simon-Good Simon-Good changed the title facedetection包含的libmnnfacedetection.so存在编译选项相关安全风险,请关注 facedetection包含的libmnnfacedetection.so存在编译选项相关安全风险,请关注解决 Jul 27, 2021
@h3clikejava
Copy link

你是审核被拒了吗?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants