CVE-2006-0539: Medium severity Thibault Godouet FCron vulnerability
Published Feb 4, 2006
·Updated
The convert-fcrontab program in fcron 3.0.0 might allow local users to gain privileges via a long command-line argument, which causes Linux glibc to report heap memory corruption, possibly because a strcpy in the strdup2 function can "overwrite some data."
Affected Software
1 affected component
Thibault Godouet FCron=3.0.0
Event History
Feb 4, 2006
CVE Published
02:02 AM
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0539?
CVE-2006-0539 is classified as a local privilege escalation vulnerability.
2
How do I fix CVE-2006-0539?
To fix CVE-2006-0539, upgrade to a version of fcron that is not affected or apply appropriate patches.
3
Who is affected by CVE-2006-0539?
Local users on systems running fcron version 3.0.0 are affected by CVE-2006-0539.
4
What are the consequences of CVE-2006-0539?
Exploitation of CVE-2006-0539 may allow local users to gain elevated privileges on the affected system.
5
Is there a known exploit for CVE-2006-0539?
Yes, there are known methods that could be utilized to exploit CVE-2006-0539 leading to possible privilege escalation.