LOW · 3.3

CVE-2010-0424

The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequently cause a denial of...

Vulnerability Description

The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequently cause a denial of service, via a symlink attack on a temporary file in the /tmp directory.

CVSS Score

3.3

LOW

AV:L/AC:M/Au:N/C:N/I:P/A:P
Confidentiality
NONE
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
FedorahostedCronie<= 1.4.3
Paul VixieVixie CronAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-0424?

CVE-2010-0424 is a vulnerability with a CVSS score of 3.3 (LOW). The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequently cause a denial of...

How severe is CVE-2010-0424?

CVE-2010-0424 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-0424?

Check the references section above for vendor advisories and patch information. Affected products include: Fedorahosted Cronie, Paul Vixie Vixie Cron.