PT-2007-1063 · Isc+1 · Vixie Cron+1

Raphael Marichez

·

Published

2007-04-16

·

Updated

2017-10-11

·

CVE-2007-1856

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: vixie-cron versions prior to 4.1-r10
Description: The issue is related to insecure permissions in vixie-cron, which can be exploited locally to cause a denial of service. This can result in cron failure due to the creation of hard links, leading to a failed st nlink check in database.c. The estimated number of potentially affected devices is not specified.
Recommendations: For versions prior to 4.1-r10, update to version 4.1-r10 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable database.c component to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-06680
BDU:2015-09564
CVE-2007-1856
RHSA-2007:0345
RHSA-2007_0345

Affected Products

Red Hat
Vixie Cron