[ Home | Liste | F.A.Q. | Risorse | Cerca... ]


[ Data: precedente | successivo | indice ] [ Argomento: precedente | successivo | indice ]


Archivio: openbsd@sikurezza.org
Soggetto: [mike<at>netxsecure.net: Updated Anti-Trojan kernel patches for OpenBSD]
Mittente: Igor Falcomata'
Data: 25 Apr 2002 02:44:55 -0000
----- Forwarded message from "Michael A. Williams" <mike<at>netxsecure.net> -----

Date: Tue, 23 Apr 2002 18:00:10 +1200
From: "Michael A. Williams" <mike<at>netxsecure.net>
X-Mailer: Mozilla 4.76 [en] (X11; U; FreeBSD 4.4-RELEASE i386)
To: openbsd security <security-announce<at>openbsd.org>
Subject: Updated Anti-Trojan kernel patches for OpenBSD

Hi,

Apologies for such a quick update,
Incorrect handling of the securelevel whereby the test for secure level
of 1 or 2 did not account for secure level greater then 2 has been
changed to test for secure level >= the desired value.

As correctly pointed out by Brett Lymn this would allow for a secure
level change above 2 with a result of disabling the signed_exec
functionality. Thanks Brett.

An updated reference implementation for OpenBSD 3.0 is available at:
http://www.trojanproof.org/sigexec-obsd3.0r-0.3.tgz

Regards,

-- 
Michael A. Williams
Security Software Engineering and InfoSec Manager
NetXSecure NZ Limited, http://www.nxs.co.nz
Ph: +64.3.318.2973 Fax: +64.3.318.2975 Mob: +64.21.995.914


----- End forwarded message -----

________________________________________________________
http://www.sikurezza.org - Italian Security Mailing List




[ Home | Liste | F.A.Q. | Risorse | Cerca... ]

www.sikurezza.org - Italian Security Mailing List
(c) 1999-2005