Vixie Cron before 4.1-r10 on Gentoo Linux is installed with insecure permissions, which allows local users to cause a denial of service (cron failure) by creating hard links, which results in a failed st_nlink check in database.c.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade sys-process/vixie-cron. | Oct 30, 2017 | Apr 17, 2007 |
| Oracle_linux | — | Upgrade vixie-cron | Oct 16, 2024 | Apr 18, 2007 |
| Suse | — | Upgrade suse-releaseUpgrade cron | Feb 17, 2015 | Apr 17, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub