Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
How not to respond to a security advisory
Jason Miller, 2006-01-18

A recently announced weakness in the BSD securelevel system isn't going to be fixed in OpenBSD. While securelevel may have problems, the vendor's security response is unacceptable and doesn't fit with their stated goals.

Submit Comment Mode:
Name:
Subject:
Message:
 
  Enter the characters that appear above
 
How not to respond to a security advisory 2006-01-19
DS
Interesting how these advisories always paint the flaw in the darkest shades possible.

Securelevels provide far more than the immutable and other flag capabilities for files. Do read the manual page:

http://www.openbsd.org/cgi-bin/man.cgi?query=securelevel&sek
tion=7&apropos=0&manpath=OpenBSD+...

[ more ]  





 

Privacy Statement
Copyright 2008, SecurityFocus