Junglewise Threat Intelligence

CVE-1999-0297: Vixie Cron buffer overflow in library

CVE-1999-0297 · Severity: high · CVSS 7.2 · Published 1996-12-12

Technologies: Bsdi Bsd Os, Freebsd, Netbsd, Redhat Linux. Vendors: Bsdi, Freebsd, Netbsd, Redhat.

Executive brief

A security vulnerability exists in a core system component used to schedule automated tasks on Unix-like operating systems. A local user with basic access to the system can exploit this flaw to gain full administrative control (root access). This could allow an attacker to view sensitive files, modify system configurations, or disrupt operations entirely.

Technical details

A buffer overflow vulnerability exists in the Vixie Cron library (up to version 3.0) due to improper bounds checking when handling environmental variables. A local, unprivileged attacker can exploit this by providing an excessively long environmental variable to the cron process. Because cron often runs with elevated privileges to execute scheduled tasks for various users, overflowing the buffer allows the attacker to overwrite memory and execute arbitrary code with root permissions. This is a classic local privilege escalation (LPE) vulnerability.

Affected products

  • Vixie Cron library up to 3.0

Timeline

  • 1996-12-12: disclosed

References

Related threats