CVE Vulnerabilities

CVE-2009-3589

Published: Oct 08, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

incron 0.5.5 does not initialize supplementary groups when running a process from a users incrontabs, which causes the process to be run with the incrond supplementary groups and allows local users to gain privileges via an incrontab table.

Affected Software

NameVendorStart VersionEnd Version
IncronInotify0.5.5 (including)0.5.5 (including)
IncronUbuntuintrepid*
IncronUbuntujaunty*
IncronUbuntukarmic*

References