PT-2017-2635 · Isc+2 · Cron+2

Alexander Peslyak

+1

·

Publicado

2017-06-09

·

Atualizado

2022-05-11

·

CVE-2017-9525

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions cron versions 3.0pl1-128 through 3.0pl1-128ubuntu2
Description The issue is related to the cron package, where the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks against unsafe usage of the chown and chmod programs. This can be exploited by an attacker to gain elevated privileges.
Recommendations For cron versions 3.0pl1-128 through 3.0pl1-128ubuntu2, consider disabling the postinst maintainer script as a temporary workaround to minimize the risk of exploitation. Restrict access to the chown and chmod programs to prevent unsafe usage. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-01862
CVE-2017-9525
DLA-1723-1
DLA-2801-1
USN-5259-1
USN-5259-2
USN-5259-3

Produtos afetados

Debian
Ubuntu
Cron