fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to delete arbitrary files or create arbitrary empty files via a target filename with a large number of leading slash (/) characters such that fcronsighup does not properly append the intended fcrontab.sig to the resulting string.
Advisories
Source ID Title
EUVD EUVD EUVD-2004-1030 fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to delete arbitrary files or create arbitrary empty files via a target filename with a large number of leading slash (/) characters such that fcronsighup does not properly append the intended fcrontab.sig to the resulting string.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-08T00:39:00.421Z

Reserved: 2004-11-12T00:00:00

Link: CVE-2004-1032

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2005-03-01T05:00:00.000

Modified: 2025-04-03T01:03:51.193

Link: CVE-2004-1032

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.