Vulnerability Description
File descriptor leak in cronie 1.4.8, when running in certain environments, might allow local users to read restricted files, as demonstrated by reading /etc/crontab.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fedorahosted | Cronie | 1.4.8 |
Related Weaknesses (CWE)
References
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:033
- https://bugs.mageia.org/show_bug.cgi?id=8652
- https://bugzilla.novell.com/show_bug.cgi?id=786096
- https://bugzilla.redhat.com/show_bug.cgi?id=893661
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:033
- https://bugs.mageia.org/show_bug.cgi?id=8652
- https://bugzilla.novell.com/show_bug.cgi?id=786096
- https://bugzilla.redhat.com/show_bug.cgi?id=893661
FAQ
What is CVE-2012-6097?
CVE-2012-6097 is a vulnerability with a CVSS score of 4.3 (MEDIUM). File descriptor leak in cronie 1.4.8, when running in certain environments, might allow local users to read restricted files, as demonstrated by reading /etc/crontab.
How severe is CVE-2012-6097?
CVE-2012-6097 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-6097?
Check the references section above for vendor advisories and patch information. Affected products include: Fedorahosted Cronie.