vendor:
by:
Michal Zalewski
7.5
CVSS
HIGH
Privilege Escalation
CWE
Product Name:
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Vixie-cron Root Exploit
This exploit targets systems running vixie cron and requires root or another chosen user to execute the 'crontab -e' or 'crontab /any/file' command. It spoofs the legitimate cron entry file with malicious content, leading to account compromise, usually resulting in root compromise.
Mitigation:
Update vixie cron to a non-vulnerable version.