CVE-2001-0685: Low severity Thibault Godouet FCron vulnerability
Published Sep 20, 2001
·Updated
Thibault Godouet FCron prior to 1.1.1 allows a local user to corrupt another user's crontab file via a symlink attack on the fcrontab temporary file.
Affected Software
5 affected components
Thibault Godouet FCron=1.0
Thibault Godouet FCron=1.0.1
Thibault Godouet FCron=1.0.2
Thibault Godouet FCron=1.0.3
Thibault Godouet FCron=1.1.0
Remediation
Patch Available
Event History
Sep 20, 2001
CVE Published
04:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0685?
CVE-2001-0685 is considered to have a medium severity level due to its potential to allow unauthorized access to crontab files.
2
How do I fix CVE-2001-0685?
To fix CVE-2001-0685, upgrade FCron to version 1.1.1 or later, where the vulnerability has been addressed.
3
Who is affected by CVE-2001-0685?
CVE-2001-0685 affects users of Thibault Godouet FCron versions prior to 1.1.1.
4
What type of attack is involved in CVE-2001-0685?
CVE-2001-0685 involves a symlink attack which allows local users to corrupt another user's crontab file.
5
When was CVE-2001-0685 published?
CVE-2001-0685 was published on July 21, 2001.