Search

published date: March 1, 2005

CVE-2004-1032 : fcronsighup in Fcron 2.0.1,...

Description

fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to delete arbitrary files or create arbitrary empty files via a target filename with a large number of leading slash (/) characters such that fcronsighup does not properly append the intended fcrontab.sig to the resulting string.

Product(s):

  • Thibault Godouet FCRON 2.0.1
  • Thibault Godouet fcron 2.9.4
  • Gentoo Linux
  • Gentoo Linux 1.2
  • Gentoo Linux 1.4

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2004-1032, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2004-1032 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?