do_command.c in Vixie cron (vixie-cron) 4.1 does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits, as originally demonstrated by a program that exceeds the process limits as defined in /etc/security/limits.conf.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vixie_cron | Paul_vixie | 4.1 (including) | 4.1 (including) |
Red Hat Enterprise Linux 4 | RedHat | vixie-cron-4:4.1-44.EL4 | * |
Cron | Ubuntu | dapper | * |
Cron | Ubuntu | devel | * |
Cron | Ubuntu | edgy | * |
Cron | Ubuntu | feisty | * |
Cron | Ubuntu | gutsy | * |
Cron | Ubuntu | hardy | * |
Cron | Ubuntu | intrepid | * |
Cron | Ubuntu | jaunty | * |
Cron | Ubuntu | upstream | * |