Sounds like your administrator would be well served to spend more time studying real-world vulnerabilities and less time focusing on SELinux :)
See eg. http://grsecurity.net/~spender/exploits/exploit2.txt
So it technically would extinguish itself there and then.
It works on the principle of least privilege so you start with nothing and add what the process needs.
Sounds like your administrator would be well served to spend more time studying real-world vulnerabilities and less time focusing on SELinux :)
See eg. http://grsecurity.net/~spender/exploits/exploit2.txt