First published: Wed Apr 18 2007(Updated: )
Vixie Cron before 4.1-r10 on Gentoo Linux is installed with insecure permissions, which allows local users to cause a denial of service (cron failure) by creating hard links, which results in a failed st_nlink check in database.c.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gentoo Linux | ||
paul Vixie Vixie cron | <=4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1856 has a moderate severity due to its potential to cause denial of service in Vixie Cron.
To fix CVE-2007-1856, ensure that Vixie Cron is upgraded to version 4.1-r10 or later, which resolves the insecure permissions issue.
CVE-2007-1856 affects users of Vixie Cron versions up to 4.1 on Gentoo Linux installations.
CVE-2007-1856 was caused by insecure file permissions that allowed local users to create hard links and disrupt cron operations.
CVE-2007-1856 cannot be exploited remotely as it requires local user access to the system.