PT-2005-2060 · Isc+1 · Vixie Cron+1

Publicado

2005-04-10

·

Atualizado

2017-10-11

·

CVE-2005-1038

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Vixie cron version 4.1
Description The issue allows local users to read the cron files of other users by changing the file being edited to a symlink when crontab is run with the -e option.
Recommendations For Vixie cron version 4.1, consider restricting access to the crontab command or implementing additional security measures to prevent unauthorized users from modifying cron files. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-1038
RHSA-2005:361
RHSA-2005_361
RHSA-2006:0117

Produtos afetados

Red Hat
Vixie Cron