fcrontab Information Disclosure Vulnerability

看板Bugtraq作者時間16年前 (2010/03/05 03:32), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D =A0fcrontab Information Disclosure Vulnerability =A0March 3, 2010 =A0CVE-2010-0792 =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D =3D=3DDescription=3D=3D fcrontab, part of the fcron scheduler, is vulnerable to several race conditions that allow a local attacker to use symbolic links to read unauthorized files.=A0 On systems where fcrontab is installed with its own "fcron" group, this allows an attacker to read other non-root users' crontabs and fcron configuration files.=A0 On systems where fcrontab is installed suid root, this allows an attacker to read arbitrary files. =3D=3DSolution=3D=3D The developer has released a new version, 3.0.5, to address these vulnerabilities.=A0 It is available for download on the developer's website, http://fcron.free.fr.=A0 Users are advised to recompile from source or download updated packages from downstream distributors when they become available. =3D=3DCredits=3D=3D This vulnerability was discovered by Dan Rosenberg (dan.j.rosenberg@gmail.com). Thanks to Thibault Godouet for his prompt response and new release. =3D=3DReferences=3D=3D CVE identifier CVE-2010-0792 has been assigned to this issue.
文章代碼(AID): #1Ba0gqTg (Bugtraq)