PT-2007-1063 · Isc+1 · Vixie Cron+1
Raphael Marichez
·
Publicado
2007-04-16
·
Atualizado
2017-10-11
·
CVE-2007-1856
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
vixie-cron versions prior to 4.1-r10
Description:
The issue is related to insecure permissions in vixie-cron, which can be exploited locally to cause a denial of service. This can result in cron failure due to the creation of hard links, leading to a failed st nlink check in database.c. The estimated number of potentially affected devices is not specified.
Recommendations:
For versions prior to 4.1-r10, update to version 4.1-r10 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable
database.c component to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Red Hat
Vixie Cron