A vulnerability has been found in fcron, allowing local attackers to conduct symlink attacks.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201311-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: fcron: Information disclosure Date: November 25, 2013 Bugs: #308075 ID: 201311-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability has been found in fcron, allowing local attackers to conduct symlink attacks. Background ========= fcron is a periodic command scheduler for Unix-based systems Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-process/fcron < 3.0.5-r2 > = 3.0.5-r2 Description ========== The fcrontab function contains a race condition relating to symlinks. Impact ===== A local attacker could perform symlink attacks to read arbitrary files with the privileges of the user running the application. Workaround ========= There is no known workaround at this time. Resolution ========= All fcron users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-process/fcron-3.0.5-r2" References ========= [ 1 ] CVE-2010-0792 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0792 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201311-16 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is ofutmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities in Fcron can allow a local user to potentially cause a Denial of Service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200411-27 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Fcron: Multiple vulnerabilities Date: November 18, 2004 Bugs: #71311 ID: 200411-27 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities in Fcron can allow a local user to potentially cause a Denial of Service. Background ========= Fcron is a command scheduler with extended capabilities over cron and anacron. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-apps/fcron = 2.0.2 > = 2.9.5.1 Description ========== Due to design errors in the fcronsighup program, Fcron may allow a local user to bypass access restrictions (CAN-2004-1031), view the contents of root owned files (CAN-2004-1030), remove arbitrary files or create empty files (CAN-2004-1032), and send a SIGHUP to any process. A vulnerability also exists in fcrontab which may allow local users to view the contents of fcron.allow and fcron.deny (CAN-2004-1033). Impact ===== A local attacker could exploit these vulnerabilities to perform a Denial of Service on the system running Fcron. Workaround ========= Make sure the fcronsighup and fcrontab binaries are only executable by trusted users. Resolution ========= All Fcron users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot--verbose "> =sys-apps/fcron-2.0.2" References ========= [ 1 ] CAN-2004-1030 https://www.cve.org/CVERecord?id=CAN-2004-1030 [ 2 ] CAN-2004-1031 https://www.cve.org/CVERecord?id=CAN-2004-1031 [ 3 ] CAN-2004-1032 https://www.cve.org/CVERecord?id=CAN-2004-1032 [ 4 ] CAN-2004-1033 https://www.cve.org/CVERecord?id=CAN-2004-1033 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200411-27 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.