PT-2001-1010 · Isc+1 · Vixie Cron+1
Published
2001-04-17
·
Updated
2017-10-10
·
CVE-2001-0559
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Vixie cron versions 3.0.1 and earlier
Description
The issue is related to a problem in crontab where it does not properly drop privileges after a failed parsing of a modification operation. This could allow a local attacker to gain additional privileges when an editor is called to correct the error. Multiple vulnerabilities in the cron package of the Debian GNU/Linux operating system can be exploited by a local attacker, potentially leading to breaches of confidentiality, integrity, and availability of protected information.
Recommendations
For Vixie cron versions 3.0.1 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Vixie Cron