Gentoo Archives: gentoo-announce

From: Matthias Geerdsen <vorlon@g.o>
To: gentoo-announce@g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200704-11 ] Vixie Cron: Denial of Service
Date: Mon, 16 Apr 2007 19:12:32
Message-Id: 4623C5A1.6070705@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200704-11
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Low
8 Title: Vixie Cron: Denial of Service
9 Date: April 16, 2007
10 Bugs: #164466
11 ID: 200704-11
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 The Gentoo implementation of Vixie Cron is vulnerable to a local Denial
19 of Service.
20
21 Background
22 ==========
23
24 Vixie Cron is a command scheduler with extended syntax over cron.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 sys-process/vixie-cron < 4.1-r10 >= 4.1-r10
33
34 Description
35 ===========
36
37 During an internal audit, Raphael Marichez of the Gentoo Linux Security
38 Team found that Vixie Cron has weak permissions set on Gentoo, allowing
39 for a local user to create hard links to system and users cron files,
40 while a st_nlink check in database.c will generate a superfluous error.
41
42 Impact
43 ======
44
45 Depending on the partitioning scheme and the "cron" group membership, a
46 malicious local user can create hard links to system or users cron
47 files that will trigger the st_link safety check and prevent the
48 targeted cron file from being run from the next restart or database
49 reload.
50
51 Workaround
52 ==========
53
54 There is no known workaround at this time.
55
56 Resolution
57 ==========
58
59 All Vixie Cron users should upgrade to the latest version:
60
61 # emerge --sync
62 # emerge --ask --oneshot --verbose ">=sys-process/vixie-cron-4.1-r10"
63
64 References
65 ==========
66
67 [ 1 ] CVE-2007-1856
68 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1856
69
70 Availability
71 ============
72
73 This GLSA and any updates to it are available for viewing at
74 the Gentoo Security Website:
75
76 http://security.gentoo.org/glsa/glsa-200704-11.xml
77
78 Concerns?
79 =========
80
81 Security is a primary focus of Gentoo Linux and ensuring the
82 confidentiality and security of our users machines is of utmost
83 importance to us. Any security concerns should be addressed to
84 security@g.o or alternatively, you may file a bug at
85 http://bugs.gentoo.org.
86
87 License
88 =======
89
90 Copyright 2007 Gentoo Foundation, Inc; referenced text
91 belongs to its owner(s).
92
93 The contents of this document are licensed under the
94 Creative Commons - Attribution / Share Alike license.
95
96 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature