Updated vixie-cron packages that fix a privilege escalation issue are now
available.
This update has been rated as having important security impact by the Red Hat
Security Response Team.
The vixie-cron package contains the Vixie version of cron. Cron is a
standard UNIX daemon that runs specified programs at scheduled times.
A privilege escalation flaw was found in the way Vixie Cron runs programs;
vixie-cron does not properly verify an attempt to set the current process
user id succeeded. It was possible for a malicious local users who
exhausted certain limits to execute arbitrary commands as root via cron.
(CVE-2006-2607)
All users of vixie-cron should upgrade to these updated packages, which
contain a backported patch to correct this issue.
| Red Hat Desktop (v. 4) |
|
| SRPMS: |
vixie-cron-4.1-44.EL4.src.rpm
File outdated by: RHBA-2009:0025 |
84ffd65a8877af47400a731ecd1b9ee3 |
| |
| IA-32: |
vixie-cron-4.1-44.EL4.i386.rpm
File outdated by: RHBA-2009:0025 |
96f8e56c7683001feb3f3af160e5d3bc |
| |
| x86_64: |
vixie-cron-4.1-44.EL4.x86_64.rpm
File outdated by: RHBA-2009:0025 |
3d045241d3453e8bc5a6bc260320fbc9 |
| |
| Red Hat Enterprise Linux AS (v. 4) |
|
| SRPMS: |
vixie-cron-4.1-44.EL4.src.rpm
File outdated by: RHBA-2009:0025 |
84ffd65a8877af47400a731ecd1b9ee3 |
| |
| IA-32: |
vixie-cron-4.1-44.EL4.i386.rpm
File outdated by: RHBA-2009:0025 |
96f8e56c7683001feb3f3af160e5d3bc |
| |
| IA-64: |
vixie-cron-4.1-44.EL4.ia64.rpm
File outdated by: RHBA-2009:0025 |
a8d8d2c094a1d9aa1e8b565633f63491 |
| |
| PPC: |
vixie-cron-4.1-44.EL4.ppc.rpm
File outdated by: RHBA-2009:0025 |
abbfe3611ef001871714d508cb12ee78 |
| |
| s390: |
vixie-cron-4.1-44.EL4.s390.rpm
File outdated by: RHBA-2009:0025 |
13a5b37c0c9c360055a75c3b779603c9 |
| |
| s390x: |
vixie-cron-4.1-44.EL4.s390x.rpm
File outdated by: RHBA-2009:0025 |
869131c337de109964f8acb2e720ee33 |
| |
| x86_64: |
vixie-cron-4.1-44.EL4.x86_64.rpm
File outdated by: RHBA-2009:0025 |
3d045241d3453e8bc5a6bc260320fbc9 |
| |
| Red Hat Enterprise Linux ES (v. 4) |
|
| SRPMS: |
vixie-cron-4.1-44.EL4.src.rpm
File outdated by: RHBA-2009:0025 |
84ffd65a8877af47400a731ecd1b9ee3 |
| |
| IA-32: |
vixie-cron-4.1-44.EL4.i386.rpm
File outdated by: RHBA-2009:0025 |
96f8e56c7683001feb3f3af160e5d3bc |
| |
| IA-64: |
vixie-cron-4.1-44.EL4.ia64.rpm
File outdated by: RHBA-2009:0025 |
a8d8d2c094a1d9aa1e8b565633f63491 |
| |
| x86_64: |
vixie-cron-4.1-44.EL4.x86_64.rpm
File outdated by: RHBA-2009:0025 |
3d045241d3453e8bc5a6bc260320fbc9 |
| |
| Red Hat Enterprise Linux WS (v. 4) |
|
| SRPMS: |
vixie-cron-4.1-44.EL4.src.rpm
File outdated by: RHBA-2009:0025 |
84ffd65a8877af47400a731ecd1b9ee3 |
| |
| IA-32: |
vixie-cron-4.1-44.EL4.i386.rpm
File outdated by: RHBA-2009:0025 |
96f8e56c7683001feb3f3af160e5d3bc |
| |
| IA-64: |
vixie-cron-4.1-44.EL4.ia64.rpm
File outdated by: RHBA-2009:0025 |
a8d8d2c094a1d9aa1e8b565633f63491 |
| |
| x86_64: |
vixie-cron-4.1-44.EL4.x86_64.rpm
File outdated by: RHBA-2009:0025 |
3d045241d3453e8bc5a6bc260320fbc9 |
| |
(The unlinked packages above are only available from the Red Hat Network)
|
193146 - CVE-2006-2607 Jobs start from root when pam_limits enabled