PDA

View Full Version : USN-778-1: cron vulnerability


rss-bot
June 1st, 2009, 02:30 PM
Referenced CVEs:
CVE-2006-2607


Description:
================================================== ========= Ubuntu Security Notice USN-778-1 June 01, 2009 cron vulnerability CVE-2006-2607 ================================================== ========= A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: cron 3.0pl1-92ubuntu1.1 Ubuntu 8.04 LTS: cron 3.0pl1-100ubuntu2.1 Ubuntu 8.10: cron 3.0pl1-104+ubuntu5.1 Ubuntu 9.04: cron 3.0pl1-105ubuntu1.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: It was discovered that cron did not properly check the return code of the setgid() and initgroups() system calls. A local attacker could use this to escalate group privileges. Please note that cron versions 3.0pl1-64 and later were already patched to address the more serious setuid() check referred to by CVE-2006-2607.





More... (http://www.ubuntu.com/usn/usn-778-1)