PT-2002-1738 · Isc · Crontab
Publicado
2002-07-26
·
Atualizado
2016-10-18
·
CVE-2002-0716
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
crontab versions 5.0.5 through 5.0.6
Description
The issue is related to a format string vulnerability in crontab, which allows local users to gain privileges. This is achieved by using format string specifiers in the file name argument.
Recommendations
For versions 5.0.5 and 5.0.6, consider restricting access to the crontab utility until a fix is available. As a temporary workaround, avoid using format string specifiers in file name arguments to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Crontab