GLSA-201311-04 : Vixie cron: Denial of Service
Low Nessus Plugin ID 70779
SynopsisThe remote Gentoo host is missing one or more security-related patches.
DescriptionThe remote host is affected by the vulnerability described in GLSA-201311-04 (Vixie cron: Denial of Service)
Vixie cron contains a race condition relating to atime and mtime values of temporary files.
A local attacker could change the modification time of files, possibly resulting in a Denial of Service condition via a symlink attack.
There is no known workaround at this time.
SolutionAll Vixie cron users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=sys-process/vixie-cron-4.1-r14'