PT-2017-2635 · Isc+2 · Cron+2
Alexander Peslyak
+1
·
Published
2017-06-09
·
Updated
2022-05-11
·
CVE-2017-9525
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
cron versions 3.0pl1-128 through 3.0pl1-128ubuntu2
Description
The issue is related to the cron package, where the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks against unsafe usage of the
chown and chmod programs. This can be exploited by an attacker to gain elevated privileges.Recommendations
For cron versions 3.0pl1-128 through 3.0pl1-128ubuntu2, consider disabling the postinst maintainer script as a temporary workaround to minimize the risk of exploitation. Restrict access to the
chown and chmod programs to prevent unsafe usage. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Ubuntu
Cron