The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 on Ubuntu 14.04 LTS, on Ubuntu Wily, and before 1:4.2.8p4+dfsg-3ubuntu5.3 on Ubuntu 16.04 LTS allows local users with access to the ntp account to write to arbitrary files and consequently gain privileges via vectors involving statistics directory cleanup.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2017-04-14T18:00:00

Updated: 2017-04-14T16:57:01

Reserved: 2015-12-16T00:00:00


Link: CVE-2016-0727

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-04-14T18:59:00.173

Modified: 2017-04-20T16:34:09.743


Link: CVE-2016-0727

JSON object: View

cve-icon Redhat Information

No data.

CWE