Lucene search

K
cveMitreCVE-2004-1033
HistoryMar 01, 2005 - 5:00 a.m.

CVE-2004-1033

2005-03-0105:00:00
mitre
web.nvd.nist.gov
36
cve-2004-1033
fcron
file descriptor leak
local users
access restrictions
nvd

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0

Percentile

5.1%

Fcron 2.0.1, 2.9.4, and possibly earlier versions leak file descriptors of open files, which allows local users to bypass access restrictions and read fcron.allow and fcron.deny via the EDITOR environment variable.

Affected configurations

Nvd
Node
thibault_godouetfcronMatch2.0.1
OR
thibault_godouetfcronMatch2.9.4
Node
gentoolinux
VendorProductVersionCPE
thibault_godouetfcron2.0.1cpe:2.3:a:thibault_godouet:fcron:2.0.1:*:*:*:*:*:*:*
thibault_godouetfcron2.9.4cpe:2.3:a:thibault_godouet:fcron:2.9.4:*:*:*:*:*:*:*
gentoolinux*cpe:2.3:o:gentoo:linux:*:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0

Percentile

5.1%