crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the crontab -e command, which allows local users with write access to the crontab spool directory to execute arbitrary commands by creating world-writeable temporary files and modifying them while the victim is editing the file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vixie_cron | Paul_vixie | 3.0_pl1 (including) | 3.0_pl1 (including) |