| |||||||||||||
| CVE ID: | CVE-2001-0559 |
| Description: | crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error. |
| Test IDs: | 1.3.6.1.4.1.25623.1.0.51467 1.3.6.1.4.1.25623.1.0.51412 |
| Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2001-0559 Bugtraq: 20010507 Vixie cron vulnerability (Google Search) http://www.securityfocus.com/archive/1/183029 Debian Security Information: DSA-054 (Google Search) http://www.debian.org/security/2001/dsa-054 http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-050.php3 SuSE Security Announcement: SuSE-SA:2001:17 (Google Search) http://www.novell.com/linux/security/advisories/2001_017_cron_txt.html BugTraq ID: 2687 http://www.securityfocus.com/bid/2687 XForce ISS Database: vixie-cron-gain-privileges(6508) http://xforce.iss.net/static/6508.php |
|