CVE-1999-0297: Buffer Overflow
Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Vixie Cron libraryfrom your environment.If the Vixie Cron library is not required on the system, uninstall/remove it to eliminate the vulnerable component until a vendor patch is available.
- Compensating control
Limit local untrusted user access to systems that run the Vixie Cron library and restrict execution of the cron binary to trusted accounts only until a vendor patch or fixed version is installed.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0297?
CVE-1999-0297 is considered a high severity vulnerability due to the potential for local users to gain root access.
How do I fix CVE-1999-0297?
To fix CVE-1999-0297, upgrade the Vixie Cron library to a version higher than 3.0.
Who is affected by CVE-1999-0297?
Local users on systems running Vixie Cron version 3.0 or earlier are affected by CVE-1999-0297.
What systems are vulnerable to CVE-1999-0297?
CVE-1999-0297 affects systems running Vixie Cron version 3.0 and specific versions of BSD, FreeBSD, and RedHat Linux.
What type of vulnerability is CVE-1999-0297?
CVE-1999-0297 is a buffer overflow vulnerability that allows for unauthorized root access through environmental variables.