Link Following Affecting cron package, versions <3.0pl1-128+deb9u2
Snyk CVSS
Attack Complexity
Low
Privileges Required
High
Confidentiality
High
Integrity
High
Availability
High
Threat Intelligence
EPSS
0.06% (26th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIAN9-CRON-311941
- published 9 Jun 2017
- disclosed 9 Jun 2017
How to fix?
Upgrade Debian:9
cron
to version 3.0pl1-128+deb9u2 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream cron
package and not the cron
package as distributed by Debian
.
See How to fix?
for Debian:9
relevant fixed versions and status.
In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks against unsafe usage of the chown and chmod programs.
References
- https://security-tracker.debian.org/tracker/CVE-2017-9525
- http://bugs.debian.org/864466
- https://lists.debian.org/debian-lts-announce/2019/03/msg00025.html
- http://www.openwall.com/lists/oss-security/2017/06/08/3
- http://www.securitytracker.com/id/1038651
- http://people.ubuntu.com/~ubuntu-security/cve/CVE-2017-9525
- https://lists.debian.org/debian-lts-announce/2021/10/msg00029.html