CVE Vulnerabilities

CVE-2004-1031

Published: Mar 01, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to bypass access restrictions and load an arbitrary configuration file by starting an suid process and pointing the fcronsighup configuration file to a /proc entry that is owned by root but modifiable by the user, such as /proc/self/cmdline or /proc/self/environ.

Affected Software

NameVendorStart VersionEnd Version
FcronThibault_godouet2.0.1 (including)2.0.1 (including)
FcronThibault_godouet2.9.4 (including)2.9.4 (including)
FcronUbuntudapper*
FcronUbuntudevel*
FcronUbuntuedgy*
FcronUbuntufeisty*

References