Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
How not to respond to a security advisory
Jason Miller, 2006-01-18

A recently announced weakness in the BSD securelevel system isn't going to be fixed in OpenBSD. While securelevel may have problems, the vendor's security response is unacceptable and doesn't fit with their stated goals.

Submit Comment Mode:
Name:
Subject:
Message:
 
  Enter the characters that appear above
 
How not to respond to a security advisory 2006-01-19
Anonymous
The comment about "useless" securelevels is odd, yes.

It should be added that this bug is really minor (yes, the chflag'ed file isn't really modified, and yes if you don't control who can mount things on the system, you'll have greater porbles). It's nearly excessive to call this a security flaw....

[ more ]  





 

Privacy Statement
Copyright 2008, SecurityFocus