CVE-2001-0559: High severity Paul Vixie Vixie Cron vulnerability
Published Aug 14, 2001
·Updated
crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error.
Affected Software
1 affected component
Paul Vixie Vixie Cron<=3.0.1
Remediation
Patch Available
Patch Available
Event History
Aug 14, 2001
CVE Published
04:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0559?
CVE-2001-0559 is considered to be of medium severity due to the potential for local privilege escalation.
2
How do I fix CVE-2001-0559?
To fix CVE-2001-0559, update Vixie cron to version 3.0.2 or later where this vulnerability is addressed.
3
Who is affected by CVE-2001-0559?
Users running Vixie cron version 3.0.1 or earlier on Unix-like systems are affected by CVE-2001-0559.
4
What type of vulnerability is CVE-2001-0559?
CVE-2001-0559 is a local privilege escalation vulnerability related to inadequate privilege dropping in cron jobs.
5
Can CVE-2001-0559 be exploited remotely?
CVE-2001-0559 cannot be exploited remotely as it requires local access to the system.