« Volver al listado

CVE-2012-6110

Estado: ModificadaBaja (2.1)—

bcron-exec in bcron before 0.10 does not close file descriptors associated with temporary files when running a cron job, which allows local users to modify job files and send spam messages by accessing an open file descriptor.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-6110",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-09-29T22:55:05.847",
  "references": [
    {
      "url": "http://seclists.org/oss-sec/2013/q1/102",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://untroubled.org/bcron/NEWS",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=686650",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/81383",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://seclists.org/oss-sec/2013/q1/102",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://untroubled.org/bcron/NEWS",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=686650",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/81383",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "bcron-exec in bcron before 0.10 does not close file descriptors associated with temporary files when running a cron job, which allows local users to modify job files and send spam messages by accessing an open file descriptor."
    },
    {
      "lang": "es",
      "value": "bcron-exec en bcron anterior a 0.10 no cierra los descriptores de ficheros asociados con ficheros temporales cuando funciona un trabajo cron, lo que permite a usuarios locales modificar ficheros de trabajos y enviar mensajes de spam mediante el acceso a un descriptor de ficheros abierto."
    }
  ],
  "lastModified": "2026-06-16T23:47:50.710",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:bcron_project:bcron_exec:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B328D9B-102E-4BA7-B03C-228A8FF6D6F2",
              "versionEndIncluding": "0.09"
            },
            {
              "criteria": "cpe:2.3:a:bcron_project:bcron_exec:0.04:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F442F3A-A281-401A-BE55-B3F59A5435D2"
            },
            {
              "criteria": "cpe:2.3:a:bcron_project:bcron_exec:0.05:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D072861B-773B-4324-A55E-59146673AF5D"
            },
            {
              "criteria": "cpe:2.3:a:bcron_project:bcron_exec:0.06:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6794F9BA-085C-43FC-A08A-6737163B0BF0"
            },
            {
              "criteria": "cpe:2.3:a:bcron_project:bcron_exec:0.07:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0BD1368A-D154-43C4-B776-C8F9C69CDD59"
            },
            {
              "criteria": "cpe:2.3:a:bcron_project:bcron_exec:0.08:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "50850227-DAE0-4AAC-90B8-26F699C996BD"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}