bcron-exec in bcron before 0.10 does not close file descriptors associated with temporary files when running a cron job, which allows local users to modify job files and send spam messages by accessing an open file descriptor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bcron_exec | Bcron_project | * | 0.09 (including) |
Bcron_exec | Bcron_project | 0.04 (including) | 0.04 (including) |
Bcron_exec | Bcron_project | 0.05 (including) | 0.05 (including) |
Bcron_exec | Bcron_project | 0.06 (including) | 0.06 (including) |
Bcron_exec | Bcron_project | 0.07 (including) | 0.07 (including) |
Bcron_exec | Bcron_project | 0.08 (including) | 0.08 (including) |
Bcron | Ubuntu | hardy | * |
Bcron | Ubuntu | lucid | * |
Bcron | Ubuntu | oneiric | * |
Bcron | Ubuntu | precise | * |
Bcron | Ubuntu | quantal | * |
Bcron | Ubuntu | upstream | * |