CVE-1999-0768: Buffer Overflow
Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable MAILTO support in cron or ensure MAILTO is not set from untrusted input; review and remove or sanitize MAILTO entries in system and user crontabs.
Vixie Cron MAILTO environment variable handling = disabled or sanitize inputs
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0768?
CVE-1999-0768 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-1999-0768?
To fix CVE-1999-0768, update the Vixie Cron package to a version that is patched against this buffer overflow vulnerability.
Which systems are affected by CVE-1999-0768?
CVE-1999-0768 affects Red Hat Linux versions 4.2, 5.2, and 6.0, as well as SUSE Linux versions 6.0 and 6.1.
What is the impact of exploiting CVE-1999-0768?
Exploiting CVE-1999-0768 can allow an attacker to execute arbitrary code with the privileges of the cron service.
Is CVE-1999-0768 still relevant today?
While CVE-1999-0768 pertains to older systems, it highlights the importance of securing legacy software against vulnerabilities.