Lucene search

K
nvd[email protected]NVD:CVE-2004-1033
HistoryMar 01, 2005 - 5:00 a.m.

CVE-2004-1033

2005-03-0105:00:00
web.nvd.nist.gov
2

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

5.1%

Fcron 2.0.1, 2.9.4, and possibly earlier versions leak file descriptors of open files, which allows local users to bypass access restrictions and read fcron.allow and fcron.deny via the EDITOR environment variable.

Affected configurations

Nvd
Node
thibault_godouetfcronMatch2.0.1
OR
thibault_godouetfcronMatch2.9.4
Node
gentoolinux
VendorProductVersionCPE
thibault_godouetfcron2.0.1cpe:2.3:a:thibault_godouet:fcron:2.0.1:*:*:*:*:*:*:*
thibault_godouetfcron2.9.4cpe:2.3:a:thibault_godouet:fcron:2.9.4:*:*:*:*:*:*:*
gentoolinux*cpe:2.3:o:gentoo:linux:*:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

5.1%