HP-UX 11.00 crontab allows local users to read arbitrary...
Low severity
Unreviewed
Published
Apr 30, 2022
to the GitHub Advisory Database
•
Updated Jan 26, 2024
Description
Published by the National Vulnerability Database
Dec 19, 2000
Published to the GitHub Advisory Database
Apr 30, 2022
Last updated
Jan 26, 2024
HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates.
References