PT-2001-1010 · Isc+1 · Vixie Cron+1

Publicado

2001-04-17

·

Atualizado

2017-10-10

·

CVE-2001-0559

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Vixie cron versions 3.0.1 and earlier
Description The issue is related to a problem in crontab where it does not properly drop privileges after a failed parsing of a modification operation. This could allow a local attacker to gain additional privileges when an editor is called to correct the error. Multiple vulnerabilities in the cron package of the Debian GNU/Linux operating system can be exploited by a local attacker, potentially leading to breaches of confidentiality, integrity, and availability of protected information.
Recommendations For Vixie cron versions 3.0.1 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-02970
CVE-2001-0559

Produtos afetados

Debian
Vixie Cron