PT-2010-1145 · Cronie+2 · Cronie+2
Dan Rosenberg
·
Publicado
2010-02-25
·
Atualizado
2024-06-15
·
CVE-2010-0424
CVSS v2.0
3.3
Baixa
| Vetor | AV:L/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
cronie versions prior to 1.4.4
Vixie cron (vixie-cron) versions prior to 4.1-r14
Description
The issue allows local users to change the modification times of arbitrary files, and consequently cause a denial of service, via a symlink attack on a temporary file in the /tmp directory. This can lead to disruption of data integrity and availability. The exploitation of this issue can be performed locally.
Recommendations
For cronie versions prior to 1.4.4, update to version 1.4.4 or later to resolve the issue.
For Vixie cron (vixie-cron) versions prior to 4.1-r14, update to version 4.1-r14 or later to resolve the issue.
As a temporary workaround, consider restricting access to the /tmp directory to minimize the risk of exploitation.
Correção
DoS
Link Following
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat
Vixie Cron
Cronie