PT-2010-1145 · Cronie+2 · Cronie+2

Dan Rosenberg

·

Published

2010-02-25

·

Updated

2024-06-15

·

CVE-2010-0424

CVSS v2.0

3.3

Low

VectorAV:L/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions cronie versions prior to 1.4.4 Vixie cron (vixie-cron) versions prior to 4.1-r14
Description The issue allows local users to change the modification times of arbitrary files, and consequently cause a denial of service, via a symlink attack on a temporary file in the /tmp directory. This can lead to disruption of data integrity and availability. The exploitation of this issue can be performed locally.
Recommendations For cronie versions prior to 1.4.4, update to version 1.4.4 or later to resolve the issue. For Vixie cron (vixie-cron) versions prior to 4.1-r14, update to version 4.1-r14 or later to resolve the issue. As a temporary workaround, consider restricting access to the /tmp directory to minimize the risk of exploitation.

Fix

DoS

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09689
CVE-2010-0424
OPENSUSE-SU-2024:10139-1
RHSA-2012:0304
RHSA-2012_0304

Affected Products

Red Hat
Vixie Cron
Cronie