First published: Wed Jan 09 2013(Updated: )
File descriptor leak in cronie 1.4.8, when running in certain environments, might allow local users to read restricted files, as demonstrated by reading /etc/crontab.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fedorahosted Cronie | =1.4.8 | |
redhat/cronie | <1.4.9 | 1.4.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-6097 has a moderate severity level, as it can lead to local users gaining unauthorized access to restricted files.
To fix CVE-2012-6097, upgrade to a version of cronie greater than 1.4.8, specifically version 1.4.9 or later.
The impact of CVE-2012-6097 allows local users to potentially read sensitive files, such as /etc/crontab, if not properly secured.
CVE-2012-6097 specifically affects cronie version 1.4.8.
CVE-2012-6097 cannot be exploited remotely; it requires local access to the system to leverage the file descriptor leak.