Where
-Infinity
0

Vendor Risk Score

See how paul vixie compares to other vendors in security performance

View Risk Score →
Severity
3.3
Race Condition
AV:L/AC:M/Au:N/C:N/I:P/A:P

Race condition was found in the way vixie-cron and cronie used to set up timestamp (modification time) for crontab file of the individual user by editing the file. A local attacker could use this flaw to conduct unintended changes of timestamp (modification time) value against various system files, potentially leading to denial of their service.

Acknowledgements:

Red Hat would like to thank Dan Rosenberg for reporting this issue.

1 / 2
Source: Red Hat
First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:N/I:N/A:P

Vixie Cron before 4.1-r10 on Gentoo Linux is installed with insecure permissions, which allows local users to cause a denial of service (cron failure) by creating hard links, which results in a failed stnlink check in database.c.

First published (updated )
Severity
7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C

docommand.c in Vixie cron (vixie-cron) 4.1 does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits, as originally demonstrated by a program that exceeds the process limits as defined in /etc/security/limits.conf.

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:P/I:N/A:N

crontab in Vixie cron 4.1, when running with the -e option, allows local users to read the cron files of other users by changing the file being edited to a symlink. NOTE: there is insufficient information to know whether this is a duplicate of CVE-2001-0235.

First published (updated )
Severity
4.6
Buffer Overflow
AV:L/AC:L/Au:N/C:P/I:P/A:P

Buffer overflow in Vixie cron 3.0.1-56 and earlier could allow a local attacker to gain additional privileges via a long username (> 20 characters).

First published (updated )
Severity
7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C

crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error.

First published (updated )
Severity
3.7
AV:L/AC:H/Au:N/C:P/I:P/A:P

crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the crontab -e command, which allows local users with write access to the crontab spool directory to execute arbitrary commands by creating world-writeable temporary files and modifying them while the victim is editing the file.

First published (updated )
Severity
7.2
Buffer Overflow
AV:L/AC:L/Au:N/C:C/I:C/A:C

Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.

First published (updated )
Severity
7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C

Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.

First published (updated )
Severity
7.2
Buffer Overflow
AV:L/AC:L/Au:N/C:C/I:C/A:C

Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203