First published: Wed Nov 24 2004(Updated: )
Fcron 2.0.1, 2.9.4, and possibly earlier versions leak file descriptors of open files, which allows local users to bypass access restrictions and read fcron.allow and fcron.deny via the EDITOR environment variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thibault Godouet FCron | =2.9.4 | |
Thibault Godouet FCron | =2.0.1 | |
Gentoo Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.