CVE-2011-1075 describes a race condition in FreeBSD's crontab utility. This vulnerability arises when crontab calculates MD5 sums to detect changes in cronjobs, specifically when using the MD5File() function with euid 0. This race condition could allow an attacker to force an arbitrary MD5 comparison, potentially bypassing read permissions. The vulnerability has a low CVSS score of 3.7, indicating a low severity. It is a network-based attack with high attack complexity, requiring no user interaction, and could lead to a limited disclosure of information. The EPSS score is very low, suggesting a minimal likelihood of exploitation. There is no evidence of active exploitation, nor are there any public exploit modules available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received no community discussion or media coverage, further indicating a lack of widespread attention or exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.