← Vulnerability feed

Vulnerability record · CVE-2001-0559 · published 14 August 2001

CVE-2001-0559: Paul vixie vixie cron vulnerability

PPaul Vixie · Vixie Cron

crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error.

7.2 CVSS 2.0 High EPSS 1.1% · top 35.4%
7.2CVSS 2.0 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error.

AV:L/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2001-0559 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2006-2607Paul vixie vixie cron vulnerabilitydo_command.c in Vixie cron (vixie-cron) 4.1 does not check the return code of a setuid call, which might allow local users to gain root privileges if…EPSS 0.57%7.2CVE-1999-0769Paul vixie vixie cron vulnerabilityVixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.EPSS 0.80%7.2CVE-1999-0872Paul vixie vixie cron vulnerabilityBuffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.EPSS 0.36%7.2CVE-1999-0297Paul vixie vixie cron vulnerabilityBuffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.EPSS 0.40%4.6CVE-2001-0560Paul vixie vixie cron vulnerabilityBuffer overflow in Vixie cron 3.0.1-56 and earlier could allow a local attacker to gain additional privileges via a long username (> 20 characters).EPSS 0.51%3.7CVE-2000-1096Paul vixie vixie cron vulnerabilitycrontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the …EPSS 0.79%3.3CVE-2010-0424Fedorahosted cronie link following vulnerabilityThe edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of …EPSS 0.35%2.1CVE-2007-1856Paul vixie vixie cron vulnerabilityVixie Cron before 4.1-r10 on Gentoo Linux is installed with insecure permissions, which allows local users to cause a denial of service (cron failure…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2001-0559), CISA KEV, FIRST EPSS (scores of 2026-10-06). This page is refreshed as NVD updates the record.