PT-2002-1738 · Isc · Crontab

Published

2002-07-26

·

Updated

2016-10-18

·

CVE-2002-0716

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions crontab versions 5.0.5 through 5.0.6
Description The issue is related to a format string vulnerability in crontab, which allows local users to gain privileges. This is achieved by using format string specifiers in the file name argument.
Recommendations For versions 5.0.5 and 5.0.6, consider restricting access to the crontab utility until a fix is available. As a temporary workaround, avoid using format string specifiers in file name arguments to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0716

Affected Products

Crontab