VulnerabilityModified
CVE-2012-6097
File descriptor leak in cronie 1.4.8, when running in certain environments, might allow local users to read restricted files, as demonstrated by reading /etc/crontab.
MEDIUM 4.3EPSS 1.35%
Does this matter?
Lower severity and a low EPSS score (1.35%). Track it; it rarely justifies an emergency change on its own.
Description
File descriptor leak in cronie 1.4.8, when running in certain environments, might allow local users to read restricted files, as demonstrated by reading /etc/crontab.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.35% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- fedorahosted/cronie
- Source
- secalert@redhat.com
References
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:033
- https://bugs.mageia.org/show_bug.cgi?id=8652
- https://bugzilla.novell.com/show_bug.cgi?id=786096
- https://bugzilla.redhat.com/show_bug.cgi?id=893661
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:033
- https://bugs.mageia.org/show_bug.cgi?id=8652
- https://bugzilla.novell.com/show_bug.cgi?id=786096
- https://bugzilla.redhat.com/show_bug.cgi?id=893661
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.