CVE-2011-1074: Infoleak
crontab.c in crontab in FreeBSD allows local users to determine the existence of arbitrary directories via a command-line argument composed of a directory name concatenated with a directory traversal sequence that leads to the /etc/crontab pathname.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1074?
CVE-2011-1074 is considered a medium severity vulnerability affecting local user access to system files.
How do I fix CVE-2011-1074?
Fixing CVE-2011-1074 involves updating to the latest version of FreeBSD where this vulnerability has been addressed.
Who is affected by CVE-2011-1074?
CVE-2011-1074 affects local users on FreeBSD systems who can exploit the vulnerability to determine the existence of arbitrary directories.
What are the potential impacts of CVE-2011-1074?
The potential impact of CVE-2011-1074 includes unauthorized access to directory existence information that could lead to further exploitation.
Is CVE-2011-1074 a remote exploit?
No, CVE-2011-1074 is not a remote exploit as it requires local user access to the FreeBSD system to be leveraged.