Vulnerability Description
In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks against unsafe usage of the chown and chmod programs.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cron Project | Cron | <= 3.0pl1-128. |
| Canonical | Ubuntu Linux | All versions |
| Debian | Debian Linux | All versions |
Related Weaknesses (CWE)
References
- http://bugs.debian.org/864466Issue TrackingThird Party AdvisoryVendor Advisory
- http://www.openwall.com/lists/oss-security/2017/06/08/3Mailing ListThird Party Advisory
- http://www.securitytracker.com/id/1038651Third Party AdvisoryVDB Entry
- https://lists.debian.org/debian-lts-announce/2019/03/msg00025.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/10/msg00029.htmlMailing ListThird Party Advisory
- http://bugs.debian.org/864466Issue TrackingThird Party AdvisoryVendor Advisory
- http://www.openwall.com/lists/oss-security/2017/06/08/3Mailing ListThird Party Advisory
- http://www.securitytracker.com/id/1038651Third Party AdvisoryVDB Entry
- https://lists.debian.org/debian-lts-announce/2019/03/msg00025.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/10/msg00029.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2017-9525?
CVE-2017-9525 is a vulnerability with a CVSS score of 6.7 (MEDIUM). In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks agai...
How severe is CVE-2017-9525?
CVE-2017-9525 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-9525?
Check the references section above for vendor advisories and patch information. Affected products include: Cron Project Cron, Canonical Ubuntu Linux, Debian Debian Linux.