rsbac 1.2.3 jail security problems

From: Bencsath Boldizsar (boldi_at_mail2003.etl.hu)
Date: 06/30/04


Date: Wed, 30 Jun 2004 16:42:10 +0200 (CEST)
To: bugtraq@securityfocus.com


Amon Ott has released a security bugfix for RSBAC 1.2.3. The problem was
discovered regarding to the RSBAC JAIL implementation. Please read the
attached original release note if interested. The bugfix is available for
download at

 http://www.rsbac.org/download/bugfixes/

For beginners, RSBAC is:
-Free Open Source (GPL) Linux kernel security extension
-Independent of governments and big companies
-Implements several well-known and new security models, e.g. MAC, ACL and
RC
-Control over individual user and program network accesses
-Any combination of models possible
-Easily extensible: write your own model for runtime registration
-Support for current kernels
-Stable for production use

----------------------



Relevant Pages

  • Re: Linux Distribution Recomendation
    ... not all distributions are created equal. ... - A kernel patch to make buffer exploits harder. ... The combination of PaX and a proper RSBAC security policy can protect against ...
    (Security-Basics)
  • Re: rsbac -- perfect solution
    ... >> are running a linux server of any sort, why would you NOT apply rsbac? ... I'll grant that MAC is important for very high ... > security environments but neither of us do. ...
    (comp.security.unix)
  • Re: rsbac -- perfect solution
    ... > are running a linux server of any sort, why would you NOT apply rsbac? ... security environments but neither of us do. ...
    (comp.security.unix)
  • Re: Linux 2.6.25.6
    ... It also contains at least one security bugfix, ... I agree that security bugfixes should be pointed out more clearly. ... obvious to bug submitters or fixers what the security implications are. ... While Brad has a good point, ...
    (Linux-Kernel)
  • Re: Security Patches to the Linux Kernel
    ... Security Patches to the Linux Kernel ... > I would be interested in learning what other peoples experiences with ... My preference goes for RSBAC for its power and the fact that you don't have ...
    (Focus-Linux)