PT-2010-1145 · Cronie+2 · Cronie+2

Dan Rosenberg

·

Publicado

2010-02-25

·

Atualizado

2024-06-15

·

CVE-2010-0424

CVSS v2.0

3.3

Baixa

VetorAV:L/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions cronie versions prior to 1.4.4 Vixie cron (vixie-cron) versions prior to 4.1-r14
Description The issue allows local users to change the modification times of arbitrary files, and consequently cause a denial of service, via a symlink attack on a temporary file in the /tmp directory. This can lead to disruption of data integrity and availability. The exploitation of this issue can be performed locally.
Recommendations For cronie versions prior to 1.4.4, update to version 1.4.4 or later to resolve the issue. For Vixie cron (vixie-cron) versions prior to 4.1-r14, update to version 4.1-r14 or later to resolve the issue. As a temporary workaround, consider restricting access to the /tmp directory to minimize the risk of exploitation.

Correção

DoS

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09689
CVE-2010-0424
OPENSUSE-SU-2024:10139-1
RHSA-2012:0304
RHSA-2012_0304

Produtos afetados

Red Hat
Vixie Cron
Cronie