PT-2001-1135 · Crontab · Crontab
Publicado
2001-01-09
·
Atualizado
2018-05-03
·
CVE-2000-1096
CVSS v2.0
3.7
Baixa
| Vetor | AV:L/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
crontab (affected versions not specified)
Description
The issue concerns the use of predictable file names for temporary files by crontab, which does not ensure proper ownership of these files by the user executing the crontab -e command. This allows local users with write access to the crontab spool directory to execute arbitrary commands. They can achieve this by creating world-writeable temporary files and modifying them while the victim is editing the file.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Crontab