>Has any one looked at the Immunix distro.  the have a few proprietary things on their site, but they also have a patch for gcc called Stack Guard, which tries to harden against buffer overflow attacks by terminating a program it detects trying to do this.
stackguard is patent pendet, a free alternative is ibm's propolice patch 
( which ashes has , 
amongst others, already included in his winter-hint 

