Vulnerabilities > CVE-2000-1096 - Unspecified vulnerability in Paul Vixie Cron 3.0Pl1

047910
CVSS 3.7 - LOW
Attack vector
LOCAL
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
high complexity
paul-vixie
exploit available

Summary

crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the crontab -e command, which allows local users with write access to the crontab spool directory to execute arbitrary commands by creating world-writeable temporary files and modifying them while the victim is editing the file.

Vulnerable Configurations

Part Description Count
Application
Paul_Vixie
1

Exploit-Db

descriptionvixie-cron Local Root Exploit. CVE-2000-1096. Local exploit for linux platform
idEDB-ID:203
last seen2016-01-31
modified2000-11-21
published2000-11-21
reporterMichal Zalewski
sourcehttps://www.exploit-db.com/download/203/
titlevixie-cron Local Root Exploit