CVE-2010-0424

Published Feb 25, 2010

Last updated 2 years ago

Overview

Description
The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequently cause a denial of service, via a symlink attack on a temporary file in the /tmp directory.
Source
secalert@redhat.com
NVD status
Modified

Social media

Hype score
Not currently trending

Risk scores

CVSS 2.0

Type
Primary
Base score
3.3
Impact score
4.9
Exploitability score
3.4
Vector string
AV:L/AC:M/Au:N/C:N/I:P/A:P

Weaknesses

nvd@nist.gov
CWE-59

Vendor comments

  • Red HatRed Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-0424 The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw.

Configurations