Vixie Cron Buffer Overflow Vulnerability
BID:602
Info
Vixie Cron Buffer Overflow Vulnerability
| Bugtraq ID: | 602 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 25 1999 12:00AM |
| Updated: | Aug 25 1999 12:00AM |
| Credit: | First exposed in RedHat advisory RHSA-1999:030-01, published on August 25, 1999. |
| Vulnerable: |
SuSE Linux 6.1 SuSE Linux 6.0 Redhat Linux 6.0 Redhat Linux 5.2 i386 Redhat Linux 4.2 |
| Not Vulnerable: |
Debian Linux 2.1 |
Discussion
Vixie Cron Buffer Overflow Vulnerability
The version of Vixie cron that ships with RedHat versions 4.2, 5.2 and 6.0 is vulnerable to a local buffer overflow attack. By utilizing the MAILTO environment variable, a buffer can be overflown in the cron_popen() function, allowing an attacker to execute arbitrary code. Vixie cron daemon is installed setuid root by default, allowing for a local root compromise. Recent versions of Debian GNU/Linux have been confirmed to not be vulnerable to this attack.
The version of Vixie cron that ships with RedHat versions 4.2, 5.2 and 6.0 is vulnerable to a local buffer overflow attack. By utilizing the MAILTO environment variable, a buffer can be overflown in the cron_popen() function, allowing an attacker to execute arbitrary code. Vixie cron daemon is installed setuid root by default, allowing for a local root compromise. Recent versions of Debian GNU/Linux have been confirmed to not be vulnerable to this attack.