Submitted by JamesStrandboge on Mon, 2009-06-01 18:20
Referenced CVEs:
CVE-2006-2607
Description:
===========================================================
Ubuntu Security Notice USN-778-1 June 01, 2009
cron vulnerability
CVE-2006-2607
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
cron 3.0pl1-92ubuntu1.1
Ubuntu 8.04 LTS:
cron 3.0pl1-100ubuntu2.1
Ubuntu 8.10:
cron 3.0pl1-104+ubuntu5.1
Ubuntu 9.04:
cron 3.0pl1-105ubuntu1.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
It was discovered that cron did not properly check the return code of
the setgid() and initgroups() system calls. A local attacker could use
this to escalate group privileges. Please note that cron versions 3.0pl1-64
and later were already patched to address the more serious setuid() check
referred to by CVE-2006-2607.


