BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: crontab from vixie-cron allows read other users crontabs Apr 06 2005 04:51PM
Richard Moore (rich westpoint ltd uk)


Karol Wiêsek wrote:
> but also checks entrys, so attacker is only able to read properly
> formated crontab files (another users crontabs).

It should be noted that files other than crontabs are valid
files as far as cron is concerned. This is because crontabs
may contain variable assignments and c...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus