Arbitrary File Deletion and Creation Vulnerability in Fcron

Arbitrary File Deletion and Creation Vulnerability in Fcron

CVE-2004-1032 · LOW Severity

AV:L/AC:L/AU:N/C:N/I:P/A:N

fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to delete arbitrary files or create arbitrary empty files via a target filename with a large number of leading slash (/) characters such that fcronsighup does not properly append the intended fcrontab.sig to the resulting string.

Learn more about our User Device Pen Test.