vixie-cron: weak permissions may cause errors
| Package(s): | vixie-cron | CVE #(s): | CVE-2007-1856 | ||||||||||||
| Created: | April 17, 2007 | Updated: | December 4, 2007 | ||||||||||||
| Description: | During an internal audit, Raphael Marichez of the Gentoo Linux Security Team found that Vixie Cron has weak permissions set on Gentoo, allowing for a local user to create hard links to system and users cron files, while a st_nlink check in database.c will generate a superfluous error. | ||||||||||||||
| Alerts: |
| ||||||||||||||
The LWN site is currently under high scraper load, so comment display has been suppressed for anonymous users. If you are a human, you may read the comments by clicking the button below:
Note: you can avoid this step in the future by logging into your LWN account.
