BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: crontab from vixie-cron allows read other users crontabs Apr 06 2005 09:31PM
David Malone (dwmalone maths tcd ie)
On Wed, Apr 06, 2005 at 12:00:48PM +0200, Karol Wi?sek wrote:
> Details:
>
> Insufficient checks allows user to change during edition regular file to
> symbolic link to any file. While copying crontab uses root permisions,
> but also checks entrys, so attacker is only able to read properly
> format...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus