Vulnerability Description
Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Paul Vixie | Vixie Cron | 3.0_pl1 |
| Caldera | Openlinux | 2.2 |
| Debian | Debian Linux | 2.1 |
| Redhat | Linux | 4.0 |
References
- http://www.securityfocus.com/bid/611
- http://www.securityfocus.com/bid/759
- http://www.securityfocus.com/bid/611
- http://www.securityfocus.com/bid/759
FAQ
What is CVE-1999-0872?
CVE-1999-0872 is a vulnerability with a CVSS score of 7.2 (HIGH). Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.
How severe is CVE-1999-0872?
CVE-1999-0872 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-1999-0872?
Check the references section above for vendor advisories and patch information. Affected products include: Paul Vixie Vixie Cron, Caldera Openlinux, Debian Debian Linux, Redhat Linux.