Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

HP Secure OS Software for Linux TLCompAdd Unauthorized File Access Vulnerability

The tlcompadd command included with HP Secure OS Software for Linux can be used to add named compartments, used to restrict the privileges of system processes. A vulnerability has been reported in some versions of this utility.

Reportedly, Mandatory Access Control (MAC) restrictions on the tlcompadd utility are insufficient. Exploitation may allow a local user to gain unauthorized access to files.







 

Privacy Statement
Copyright 2009, SecurityFocus