PT-2006-1031 · Isc+1 · Vixie Cron+1

Roman Veretelnikov

·

Published

2006-05-25

·

Updated

2024-06-15

·

CVE-2006-2607

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: vixie-cron version 4.1 vixie-cron versions prior to 4.1-r9
Description: The issue is related to a lack of return code checking for a setuid call in do command.c, potentially allowing local users to gain root privileges under certain conditions, such as PAM failures or resource limits. This could lead to a breach of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be performed locally.
Recommendations: For vixie-cron version 4.1, update to a version that includes the fix for this issue. For vixie-cron versions prior to 4.1-r9, update to version 4.1-r9 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive resources and monitoring system logs for suspicious activity until a patch is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-04882
BDU:2015-09513
CVE-2006-2607
OPENSUSE-SU-2024:10139-1
RHSA-2006:0539
RHSA-2006_0539

Affected Products

Red Hat
Vixie Cron