CVE-2004-1033: Low severity Thibault Godouet FCron vulnerability
Published Nov 24, 2004
·Updated
Fcron 2.0.1, 2.9.4, and possibly earlier versions leak file descriptors of open files, which allows local users to bypass access restrictions and read fcron.allow and fcron.deny via the EDITOR environment variable.
Affected Software
3 affected components
Thibault Godouet FCron=2.0.1
Thibault Godouet FCron=2.9.4
Gentoo Linux
Remediation
Patch Available
Event History
Nov 24, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1033?
CVE-2004-1033 has a medium severity rating due to the potential for local users to bypass access restrictions.
2
How do I fix CVE-2004-1033?
To fix CVE-2004-1033, update Fcron to version 2.9.5 or later to prevent file descriptor leakage.
3
Which versions of Fcron are affected by CVE-2004-1033?
CVE-2004-1033 affects Fcron versions 2.0.1 and 2.9.4, and possibly earlier versions.
4
Can local users exploit CVE-2004-1033?
Yes, local users can exploit CVE-2004-1033 to read sensitive access control files like fcron.allow and fcron.deny.
5
Is this vulnerability present in Gentoo Linux?
Yes, Gentoo Linux is listed among the affected systems for CVE-2004-1033, particularly with the vulnerable versions of Fcron.