PT-2001-1010 · Isc+1 · Vixie Cron+1

Published

2001-04-17

·

Updated

2017-10-10

·

CVE-2001-0559

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Vixie cron versions 3.0.1 and earlier
Description The issue is related to a problem in crontab where it does not properly drop privileges after a failed parsing of a modification operation. This could allow a local attacker to gain additional privileges when an editor is called to correct the error. Multiple vulnerabilities in the cron package of the Debian GNU/Linux operating system can be exploited by a local attacker, potentially leading to breaches of confidentiality, integrity, and availability of protected information.
Recommendations For Vixie cron versions 3.0.1 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-02970
CVE-2001-0559

Affected Products

Debian
Vixie Cron