Bug#686650: bcron: Possible bcron security breach

2013-01-17 Thread Jonathan Wiltshire
Package: bcron Dear maintainer, Recently you fixed one or more security problems and as a result you closed this bug. These problems were not serious enough for a Debian Security Advisory, so they are now on my radar for fixing in the following suites through point releases: squeeze (6.0.7) - us

Bug#686650: bcron: Possible bcron security breach

2012-09-04 Thread Anton Khalikov
Package: bcron Version: 0.09-12 Severity: normal Tags: upstream Dear Maintainer, I think I have found a security breach in bcron. Bcron-exec program does not close its file descriptors when does fork()/exec() to run scheduled jobs. When used in untrusted environment such as shared hosting, it