First published: Tue Feb 16 2010(Updated: )
The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequently cause a denial of service, via a symlink attack on a temporary file in the /tmp directory.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fedorahosted Cronie | <=1.4.3 | |
Paul Vixie Vixie Cron | ||
redhat/vixie-cron | <4:4.1-81.el5 | 4:4.1-81.el5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.