Bugtraq mailing list archives

Re: Security Hole in Axent ESM


From: patrick () CS VIRGINIA EDU (Patrick)
Date: Wed, 2 Sep 1998 14:50:57 -0400


Yes. Process capability restrictions. CAP_TIME or something like that could
be easily implemented.

Looks like it already has.  (Except that capabilities still aren't in the
ext2 code of mainstream kernels, are they?)

Look in kernel 2.1.119 at include/linux/capability.h, lines 246-250 and
kernel/time.c, lines 155-160.

--Patrick



Current thread: