|
Fedora Core vixie-cron Exposure of Arbitrary Cron Files
|
|
Secunia Advisory:
|
SA14862
|
|
|
Release Date:
|
2005-04-08
|
|
Last Update:
|
2005-07-13
|
|
Popularity:
|
7,354 views
|
|
|
Critical:
|
 Not critical
|
|
Impact:
|
Exposure of system information
|
|
Where:
|
Local system
|
|
Solution Status:
|
Vendor Patch
|
|
| OS: | Fedora Core 3 Fedora Core 4
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2005-1038
|
|
Description: Karol Wiêsek has discovered a vulnerability in vixie-cron on Fedora Core, which can be exploited by malicious, local users to read arbitrary cron files.
The vulnerability is caused due to a missing check of the temporary file edited by the user. This can be exploited by removing the temporary cron file while it is being edited and replace it with a symbolic link to arbitrary cron files.
The vulnerability has been confirmed on a fully updated Fedora Core 3 system.
NOTE: This issue appears to be similar to an issue, which was reported in vixie-cron in year 2000 and subsequently fixed in some other distributions.
Solution: Apply updated packages.
Fedora Core 3:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
4a9fab23c95a42cbfab6826da467dd9e SRPMS/vixie-cron-4.1-36.FC3.src.rpm
066fda9ad1b88913a439a43db1db5ff2 x86_64/vixie-cron-4.1-36.FC3.x86_64.rpm
288bc505eb47611dc100fc916e003574 x86_64/debug/vixie-cron-debuginfo-4.1-36.FC3.x86_64.rpm
6ebbce985d0f6ded53fbb73c17b8f268 i386/vixie-cron-4.1-36.FC3.i386.rpm
e220e2e902d1af9dec1fbd8862f9b0ca i386/debug/vixie-cron-debuginfo-4.1-36.FC3.i386.rpm
Fedora Core 4:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/
ad172e334ca71e6652e9d202dbc3593a SRPMS/vixie-cron-4.1-36.FC4.src.rpm
cf81e9e4304d0d0e2b1c17067c9e5ac2 ppc/vixie-cron-4.1-36.FC4.ppc.rpm
89f88c5d0446ea1f175a22c538591f2e ppc/debug/vixie-cron-debuginfo-4.1-36.FC4.ppc.rpm
12bb9d2d160704155aba8b6df075083e x86_64/vixie-cron-4.1-36.FC4.x86_64.rpm
2524c47f6696b16558748b26a1ba25f5 x86_64/debug/vixie-cron-debuginfo-4.1-36.FC4.x86_64.rpm
c6198a1727d17635adbed340e57ea6a4 i386/vixie-cron-4.1-36.FC4.i386.rpm
4e1fe756aa865c2ae06f945fc7874095 i386/debug/vixie-cron-debuginfo-4.1-36.FC4.i386.rpm
Provided and/or discovered by: Karol Wiêsek
Changelog: 2005-07-13: New packages released for FC3 and FC4. Updated "Solution" and "OS Information" sections.
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|