bcron-exec in bcron before 0.10 does not close file descriptors associated with temporary files when running a cron job, which allows local users to modify job files and send spam messages by accessing an open file descriptor.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=686650 | patch exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/81383 | vdb entry |
http://seclists.org/oss-sec/2013/q1/102 | mailing list |
http://untroubled.org/bcron/NEWS |