CVE-2011-1075 Information
Jun 07, 2022
cve
Description
FreeBSD’s crontab calculates the MD5 sum of the previous and new cronjob to determine if any changes have been made before copying the new version in. In particular it uses the MD5File() function which takes a pathname as an argument and is called with euid 0. A race condition in this process may lead to an arbitrary MD5 comparison regardless of the read permissions.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
https://marc.info/?l=full-disclosure&m=129891323028897&w=2 https://www.openwall.com/lists/oss-security/2011/02/28/14 https://security.netapp.com/advisory/ntap-20211125-0004/
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
3.7
Share on: