PT-2005-2060 · Isc+1 · Vixie Cron+1

Published

2005-04-10

·

Updated

2017-10-11

·

CVE-2005-1038

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Vixie cron version 4.1
Description The issue allows local users to read the cron files of other users by changing the file being edited to a symlink when crontab is run with the -e option.
Recommendations For Vixie cron version 4.1, consider restricting access to the crontab command or implementing additional security measures to prevent unauthorized users from modifying cron files. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1038
RHSA-2005:361
RHSA-2005_361
RHSA-2006:0117

Affected Products

Red Hat
Vixie Cron