Fcron FCronTab/FCronSighUp Multiple Local Vulnerabilities

BID:11684

Info

Fcron FCronTab/FCronSighUp Multiple Local Vulnerabilities

Bugtraq ID: 11684
Class: Design Error
CVE: CVE-2004-1030
CVE-2004-1031
CVE-2004-1032
CVE-2004-1033
Remote: No
Local: Yes
Published: Nov 15 2004 12:00AM
Updated: Jul 12 2009 08:06AM
Credit: Discovery of these vulnerabilities is credited to Karol Wiesek.
Vulnerable: Gentoo Linux
Fcron Fcron 2.9.4
Fcron Fcron 2.0.1
Not Vulnerable: Fcron Fcron 2.9.5 .1
Fcron Fcron 2.0.2

Discussion

Fcron FCronTab/FCronSighUp Multiple Local Vulnerabilities

Fcron is reported prone to multiple local vulnerabilities. The following issues are reported:

A local information disclosure vulnerability is reported to affect fcronsighup. It is reported that the affected utility will attempt to parse configuration files that are passed to the utility as a command line argument.

A local attacker may exploit this condition to reveal the contents of arbitrary files that are owned by the superuser. This vulnerability is assigned the following MITRE CVE identifier: CAN-2004-1030.

An access control bypass vulnerability is also reported to affect fcronsighup. It is reported that the issue exists due to a design error.

A local attacker may exploit this vulnerability to make configuration changes to fcronsighup. This vulnerability is assigned the following MITRE CVE identifier: CAN-2004-1031.

fcronsighup is reported prone to an arbitrary file deletion vulnerability. By exploiting the aforementioned access control bypass vulnerability, a local attacker may influence the fcronsighup configuration and may cause the application to overwrite arbitrary attacker specified files. This vulnerability is assigned the following MITRE CVE identifier: CAN-2004-1032.

Finally it is reported that the fcrontab component of Fcron leaks file descriptors. This can result in sensitive information disclosure. Specifically, fcrontab leaks the file descriptors of the '/etc/fcron.allow' and '/etc/fcron.deny' files. This vulnerability is assigned the following MITRE CVE identifier: CAN-2004-1033.

Exploit / POC

Fcron FCronTab/FCronSighUp Multiple Local Vulnerabilities

No exploit is required.

Solution / Fix

Fcron FCronTab/FCronSighUp Multiple Local Vulnerabilities

Solution:
Gentoo Linux has released advisory GLSA 200411-27 to address these issues. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=sys-apps/fcron-2.0.2"
Please see the referenced advisory for further information.

The vendor has released the upgrades to address these vulnerabilities.

Trustix has released advisory TSLSA-2005-0001 to address various issues. Please see the referenced advisory for more information.


Fcron Fcron 2.0.1

Fcron Fcron 2.9.4

References

Fcron FCronTab/FCronSighUp Multiple Local Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report