Описание
In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks against unsafe usage of the chown and chmod programs.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | released | 3.0pl1-128.1ubuntu1.2 |
| cosmic | ignored | end of life |
| devel | not-affected | 3.0pl1-134ubuntu1 |
| disco | ignored | end of life |
| eoan | not-affected | 3.0pl1-134ubuntu1 |
| esm-infra-legacy/trusty | needed | |
| esm-infra/bionic | released | 3.0pl1-128.1ubuntu1.2 |
| esm-infra/focal | not-affected | 3.0pl1-134ubuntu1 |
| esm-infra/xenial | released | 3.0pl1-128ubuntu2+esm2 |
Показывать по
6.9 Medium
CVSS2
6.7 Medium
CVSS3
Связанные уязвимости
In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks against unsafe usage of the chown and chmod programs.
In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-1 ...
In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks against unsafe usage of the chown and chmod programs.
Уязвимость демона-планировщика задач в UNIX-подобных операционных системах Cron, позволяющая нарушителю расширить привилегии
6.9 Medium
CVSS2
6.7 Medium
CVSS3