PT-2007-1063 · Isc+1 · Vixie Cron+1

Raphael Marichez

·

Publicado

2007-04-16

·

Atualizado

2017-10-11

·

CVE-2007-1856

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: vixie-cron versions prior to 4.1-r10
Description: The issue is related to insecure permissions in vixie-cron, which can be exploited locally to cause a denial of service. This can result in cron failure due to the creation of hard links, leading to a failed st nlink check in database.c. The estimated number of potentially affected devices is not specified.
Recommendations: For versions prior to 4.1-r10, update to version 4.1-r10 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable database.c component to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-06680
BDU:2015-09564
CVE-2007-1856
RHSA-2007:0345
RHSA-2007_0345

Produtos afetados

Red Hat
Vixie Cron