Bug: fcrontab 3.0.4 Information Disclosure Vulnerability (WLB-2010030172 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: fcrontab 3.0.4 Information Disclosure Vulnerability
 Credit: Dan Rosenberg
 Date: 2010.03.09
 CWE: CWE-59 (Show similar)
 CVE: CVE-2010-0792 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Medium
Yes
No

============================================
 fcrontab Information Disclosure Vulnerability
 March 3, 2010
 CVE-2010-0792
============================================

==Description==

fcrontab, part of the fcron scheduler, is vulnerable to several race
conditions that allow a local attacker to use symbolic links to read
unauthorized files.  On systems where fcrontab is installed with its
own "fcron" group, this allows an attacker to read other non-root
users' crontabs and fcron configuration files.  On systems where
fcrontab is installed suid root, this allows an attacker to read arbitrary
files.

==Solution==

The developer has released a new version, 3.0.5, to address these
vulnerabilities.  It is available for download on the developer's
website, http://fcron.free.fr.  Users are advised to recompile from
source or download updated packages from downstream distributors
when they become available.

==Credits==

This vulnerability was discovered by Dan Rosenberg
(dan.j.rosenberg (at) gmail (dot) com [email concealed]).
Thanks to Thibault Godouet for his prompt response and new release.

==References==

CVE identifier CVE-2010-0792 has been assigned to this issue.

References:

http://www.securityfocus.com/bid/38531
http://fcron.free.fr/
http://xforce.iss.net/xforce/xfdb/56680
http://www.securityfocus.com/archive/1/archive/1/509873/100/0/threaded
http://www.osvdb.org/62718
http://securitytracker.com/id?1023677
http://secunia.com/advisories/38796

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com