Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
How not to respond to a security advisory
Jason Miller, 2006-01-18

A recently announced weakness in the BSD securelevel system isn't going to be fixed in OpenBSD. While securelevel may have problems, the vendor's security response is unacceptable and doesn't fit with their stated goals.

Submit Comment Mode:
Name:
Subject:
Message:
 
  Enter the characters that appear above
 
How not to respond to a security advisory 2006-01-20
Fred Cohen
The OpenBSD people are correct. They are really only a vaneer of security and not a realistic protection mechanism. They are readily defeated by a user who is root regardless of any claims that they would not be, and this cannot be undone because root has access to all of memory and all of the hardw...

[ more ]  





 

Privacy Statement
Copyright 2008, SecurityFocus