Executive brief
A security vulnerability exists in the task scheduling service (crond) of Slackware Linux. This service is responsible for running automated background tasks at specific times. An attacker with local access to the system could exploit this flaw to gain full administrative control (root access), potentially leading to complete system compromise and data theft.
Technical details
A buffer overflow vulnerability exists within the crond daemon in Slackware Linux. The flaw is triggered during the processing of specific inputs, though the exact vulnerable parameter is not specified in the legacy advisory. Because crond typically runs with elevated privileges to manage system-wide tasks, a local attacker can exploit this memory corruption to execute arbitrary code with root permissions. This allows for a complete privilege escalation from a standard user to the system administrator. The vulnerability is accessible to any user with local shell access.
Affected products
- Slackware Slackware Linux Unknown
Timeline
- 1997-12-01: disclosed: Initial publication date