CVE-2006-0575: Medium severity Thibault Godouet FCron vulnerability
Published Feb 7, 2006
·Updated
convert-fcrontab in Fcron 2.9.5 and 3.0.0 allows remote attackers to create or overwrite arbitrary files via ".." sequences and a symlink attack on the temporary file that is used during conversion.
Affected Software
2 affected components
Thibault Godouet FCron=2.9.5
Thibault Godouet FCron=3.0.0
Event History
Feb 7, 2006
CVE Published
08:02 PM
Feb 8, 2006
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0575?
CVE-2006-0575 is considered a high-severity vulnerability due to the potential for remote attackers to exploit it to overwrite arbitrary files.
2
How do I fix CVE-2006-0575?
To fix CVE-2006-0575, upgrade to Fcron version 3.0.1 or later, which addresses this vulnerability.
3
What types of attacks are possible with CVE-2006-0575?
CVE-2006-0575 allows remote attackers to execute symlink attacks, leading to file manipulation on the target system.
4
Which versions of Fcron are affected by CVE-2006-0575?
Fcron versions 2.9.5 and 3.0.0 are both affected by CVE-2006-0575.
5
Can CVE-2006-0575 be exploited without authentication?
Yes, CVE-2006-0575 can be exploited by remote attackers without requiring authentication.