CVE-2004-1032
fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to delete arbitrary files or create arbitrary empty files via a target filename with a large number of leading slash (/) characters such that fcronsighup does not…
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to delete arbitrary files or create arbitrary empty files via a target filename with a large number of leading slash (/) characters such that fcronsighup does not properly append the intended fcrontab.sig to the resulting string.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Affected
- thibault godouet/fcron · gentoo/linux
- Source
- cve@mitre.org
References
- http://security.gentoo.org/glsa/glsa-200411-27.xmlPatch, Vendor Advisory
- http://www.idefense.com/application/poi/display?id=157&type=vulnerabilities&flashstatus=false
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18077
- http://security.gentoo.org/glsa/glsa-200411-27.xmlPatch, Vendor Advisory
- http://www.idefense.com/application/poi/display?id=157&type=vulnerabilities&flashstatus=false
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18077
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.