PT-2017-2635 · Isc+2 · Cron+2

Alexander Peslyak

+1

·

Published

2017-06-09

·

Updated

2022-05-11

·

CVE-2017-9525

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions cron versions 3.0pl1-128 through 3.0pl1-128ubuntu2
Description The issue is related to the cron package, where the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks against unsafe usage of the chown and chmod programs. This can be exploited by an attacker to gain elevated privileges.
Recommendations For cron versions 3.0pl1-128 through 3.0pl1-128ubuntu2, consider disabling the postinst maintainer script as a temporary workaround to minimize the risk of exploitation. Restrict access to the chown and chmod programs to prevent unsafe usage. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-01862
CVE-2017-9525
DLA-1723-1
DLA-2801-1
USN-5259-1
USN-5259-2
USN-5259-3

Affected Products

Debian
Ubuntu
Cron