[cciug] Major clearcase security hole

From: ken loehr (kloehr@webmail.bellsouth.net)
Date: Fri Feb 18 2000 - 17:44:45 EST


Hello CCiUGers,

I have found a very disturbing security hole in ClearCase. When I perform a checkout of a file to my view not only is the file copied to my view, but is also made writable in the file system. This is as you can imagine a major hole since now anyone who has access to that machine could MODIFY YOUR SORCE CODE ! I think that Rational should lock the file within the view so that it is writable there and leave the copy in the filesystem read only, then when the file is checked in the changes can apply. This would close this major hole in Clearcases security.

-Kenneth Loehr
 Senior Director Engineering

 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -



This archive was generated by hypermail 2b29 : Sun May 06 2001 - 00:23:20 EDT