CVE-2012-6097
Published Apr 9, 2013File descriptor leak in cronie 1.4.8, when running in certain environments, might allow local users to read restricted files, as demonstrated by reading /etc/crontab.
Vendor/product archive
2 CVEs tagged to fedorahosted / cronie — 0 Critical, 0 High, 1 Medium, 1 Low, 0 Unrated.
File descriptor leak in cronie 1.4.8, when running in certain environments, might allow local users to read restricted files, as demonstrated by reading /etc/crontab.
The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequen…