PT-2010-1145 · Cronie+2 · Cronie+2
Dan Rosenberg
·
Published
2010-02-25
·
Updated
2024-06-15
·
CVE-2010-0424
CVSS v2.0
3.3
Low
| Vector | AV:L/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
cronie versions prior to 1.4.4
Vixie cron (vixie-cron) versions prior to 4.1-r14
Description
The issue allows local users to change the modification times of arbitrary files, and consequently cause a denial of service, via a symlink attack on a temporary file in the /tmp directory. This can lead to disruption of data integrity and availability. The exploitation of this issue can be performed locally.
Recommendations
For cronie versions prior to 1.4.4, update to version 1.4.4 or later to resolve the issue.
For Vixie cron (vixie-cron) versions prior to 4.1-r14, update to version 4.1-r14 or later to resolve the issue.
As a temporary workaround, consider restricting access to the /tmp directory to minimize the risk of exploitation.
Fix
DoS
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat
Vixie Cron
Cronie