CVE-2017-9525: Medium severity Cron Project Cron vulnerability
Published Jun 9, 2017
·Updated
In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks against unsafe usage of the chown and chmod programs.
Affected Software
5 affected components
Cron Project Cron<=3.0pl1-128.
Canonical Ubuntu Linux
Debian Debian Linux
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Event History
Jun 9, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9525?
CVE-2017-9525 is considered a high severity vulnerability due to the potential for privilege escalation.
2
How do I fix CVE-2017-9525?
To fix CVE-2017-9525, update the cron package to a version greater than 3.0pl1-128.
3
What type of attack is associated with CVE-2017-9525?
CVE-2017-9525 is vulnerable to symlink attacks that exploit unsafe chown and chmod usage.
4
What is the impact of exploiting CVE-2017-9525?
Exploiting CVE-2017-9525 allows an attacker to gain root privileges on vulnerable systems.
5
On which systems is CVE-2017-9525 applicable?
CVE-2017-9525 affects cron versions up to 3.0pl1-128 on Debian and Ubuntu systems.