PT-2001-1135 · Crontab · Crontab

Publicado

2001-01-09

·

Atualizado

2018-05-03

·

CVE-2000-1096

CVSS v2.0

3.7

Baixa

VetorAV:L/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions crontab (affected versions not specified)
Description The issue concerns the use of predictable file names for temporary files by crontab, which does not ensure proper ownership of these files by the user executing the crontab -e command. This allows local users with write access to the crontab spool directory to execute arbitrary commands. They can achieve this by creating world-writeable temporary files and modifying them while the victim is editing the file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2000-1096

Produtos afetados

Crontab