CVE Vulnerabilities

CVE-2004-1031

Published: Mar 01, 2005 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to bypass access restrictions and load an arbitrary configuration file by starting an suid process and pointing the fcronsighup configuration file to a /proc entry that is owned by root but modifiable by the user, such as /proc/self/cmdline or /proc/self/environ.

Affected Software

Name Vendor Start Version End Version
Fcron Thibault_godouet 2.0.1 (including) 2.0.1 (including)
Fcron Thibault_godouet 2.9.4 (including) 2.9.4 (including)
Fcron Ubuntu dapper *
Fcron Ubuntu devel *
Fcron Ubuntu edgy *
Fcron Ubuntu feisty *

References