Lucene search

K
centosCentOS ProjectCESA-2007:0345
HistoryMay 17, 2007 - 4:28 p.m.

vixie security update

2007-05-1716:28:05
CentOS Project
lists.centos.org
44

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

0.058 Low

EPSS

Percentile

93.4%

CentOS Errata and Security Advisory CESA-2007:0345

The vixie-cron package contains the Vixie version of cron. Cron is a
standard UNIX daemon that runs specified programs at scheduled times.

Raphael Marichez discovered a denial of service bug in the way vixie-cron
verifies crontab file integrity. A local user with the ability to create a
hardlink to /etc/crontab can prevent vixie-cron from executing certain
system cron jobs. (CVE-2007-1856)

All users of vixie-cron should upgrade to these updated packages, which
contain a backported patch to correct this issue.

Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2007-May/075930.html
https://lists.centos.org/pipermail/centos-announce/2007-May/075932.html
https://lists.centos.org/pipermail/centos-announce/2007-May/075933.html
https://lists.centos.org/pipermail/centos-announce/2007-May/075934.html
https://lists.centos.org/pipermail/centos-announce/2007-May/075948.html
https://lists.centos.org/pipermail/centos-announce/2007-May/075949.html
https://lists.centos.org/pipermail/centos-announce/2007-May/075955.html
https://lists.centos.org/pipermail/centos-announce/2007-May/075958.html
https://lists.centos.org/pipermail/centos-announce/2007-May/075968.html
https://lists.centos.org/pipermail/centos-announce/2007-May/075969.html

Affected packages:
vixie-cron

Upstream details at:
https://access.redhat.com/errata/RHSA-2007:0345

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

0.058 Low

EPSS

Percentile

93.4%