The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequently cause a denial of service, via a symlink attack on a temporary file in the /tmp directory.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cronie | Fedorahosted | * | 1.4.3 (including) |
Vixie_cron | Paul_vixie | * | * |
Red Hat Enterprise Linux 5 | RedHat | vixie-cron-4:4.1-81.el5 | * |