OpenBSD Default Crontab root Compromise Vulnerability

BID:4495

Info

OpenBSD Default Crontab root Compromise Vulnerability

Bugtraq ID: 4495
Class: Environment Error
CVE:
Remote: Unknown
Local: Yes
Published: Apr 11 2002 12:00AM
Updated: Apr 11 2002 12:00AM
Credit: Discovered by Milos Urbanek <[email protected]>.
Vulnerable: OpenBSD OpenBSD 2.9
OpenBSD OpenBSD 3.0
Not Vulnerable:

Discussion

OpenBSD Default Crontab root Compromise Vulnerability

OpenBSD ships with a number of cron jobs configured by default. The tasks are for the purpose of summarizing system information.

The mail(1) utility is used to send the summaries to the root user. This utility supports escaped characters in message text indicating commands to be executed during processing.

If attacker-supplied data can be included in the message text passed to mail(1), commands specified by the attacker may be executed as root. If the attacker embeds the escape sequence followed by an arbitrary command in this data, the commands will be executed as root when the cron task runs. It is possible for an attacker to embed data in filenames, which are included in the emails.

Exploit / POC

OpenBSD Default Crontab root Compromise Vulnerability

Przemyslaw Frasunek <[email protected]> has made an exploit available.

CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.

Solution / Fix

OpenBSD Default Crontab root Compromise Vulnerability

Solution:
An CVS fix is available from OpenBSD:


OpenBSD OpenBSD 3.0

References

OpenBSD Default Crontab root Compromise Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report