Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-1075

Опубликовано: 19 окт. 2021
Источник: nvd
CVSS3: 3.7
CVSS2: 4.3
EPSS Низкий

Описание

FreeBSD's crontab calculates the MD5 sum of the previous and new cronjob to determine if any changes have been made before copying the new version in. In particular, it uses the MD5File() function, which takes a pathname as an argument, and is called with euid 0. A race condition in this process may lead to an arbitrary MD5 comparison regardless of the read permissions.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:freebsd:freebsd:-:*:*:*:*:*:*:*

EPSS

Процентиль: 42%
0.00197
Низкий

3.7 Low

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-362
CWE-362

Связанные уязвимости

CVSS3: 3.7
debian
больше 4 лет назад

FreeBSD's crontab calculates the MD5 sum of the previous and new cronj ...

github
почти 4 года назад

FreeBSD's crontab calculates the MD5 sum of the previous and new cronjob to determine if any changes have been made before copying the new version in. In particular, it uses the MD5File() function, which takes a pathname as an argument, and is called with euid 0. A race condition in this process may lead to an arbitrary MD5 comparison regardless of the read permissions.

EPSS

Процентиль: 42%
0.00197
Низкий

3.7 Low

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-362
CWE-362