Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: crontab from vixie-cron allows read other users crontabs Apr 06 2005 08:24PM
Gadi Evron (ge linuxbox org)
Karol Wiêsek wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Name: vixie-cron

[snip]

> Details:
>
> Insufficient checks allows user to change during edition regular file to
> symbolic link to any file. While copying crontab uses root permisions,
> but also checks entrys, so attack...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus