Lucene search

K
ubuntucveUbuntu.comUB:CVE-2004-1031
HistoryMar 01, 2005 - 12:00 a.m.

CVE-2004-1031

2005-03-0100:00:00
ubuntu.com
ubuntu.com
11

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS

0

Percentile

5.1%

fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows
local users to bypass access restrictions and load an arbitrary
configuration file by starting an suid process and pointing the fcronsighup
configuration file to a /proc entry that is owned by root but modifiable by
the user, such as /proc/self/cmdline or /proc/self/environ.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchfcron< 3.0.0-2UNKNOWN
ubuntu6.10noarchfcron< 3.0.0-2UNKNOWN
ubuntu7.04noarchfcron< 3.0.0-2UNKNOWN

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS

0

Percentile

5.1%