← Vulnerability feed

Vulnerability record · CVE-2006-2607 · published 25 May 2006

CVE-2006-2607: Paul vixie vixie cron vulnerability

PPaul Vixie · Vixie Cron

do_command.c in Vixie cron (vixie-cron) 4.1 does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits, as originally demonstrated by a program that exceeds the process limits as defined in /etc/security/limits.conf.

7.2 CVSS 2.0 High EPSS 0.57% · top 54.9%
7.2CVSS 2.0 base score
0.57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
38References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

do_command.c in Vixie cron (vixie-cron) 4.1 does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits, as originally demonstrated by a program that exceeds the process limits as defined in /etc/security/limits.conf.

AV:L/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugs.gentoo.org/show_bug.cgi?id=134194
http://secunia.com/advisories/20380 Vendor Advisory
http://secunia.com/advisories/20388
http://secunia.com/advisories/20616
http://secunia.com/advisories/21032
http://secunia.com/advisories/21702
http://secunia.com/advisories/35318
http://security.gentoo.org/glsa/glsa-200606-07.xml
http://securitytracker.com/id?1016480
http://support.avaya.com/elmodocs2/security/ASA-2006-168.htm
http://www.novell.com/linux/security/advisories/2006-05-32.html
http://www.redhat.com/support/errata/RHSA-2006-0539.html
http://www.securityfocus.com/archive/1/435033/100/0/threaded
http://www.securityfocus.com/bid/18108
http://www.vupen.com/english/advisories/2006/2075
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=178431 ExploitPatch
https://exchange.xforce.ibmcloud.com/vulnerabilities/26691
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10213
https://usn.ubuntu.com/778-1/
http://bugs.gentoo.org/show_bug.cgi?id=134194
http://secunia.com/advisories/20380 Vendor Advisory
http://secunia.com/advisories/20388
http://secunia.com/advisories/20616
http://secunia.com/advisories/21032
http://secunia.com/advisories/21702
http://secunia.com/advisories/35318
http://security.gentoo.org/glsa/glsa-200606-07.xml
http://securitytracker.com/id?1016480
http://support.avaya.com/elmodocs2/security/ASA-2006-168.htm
http://www.novell.com/linux/security/advisories/2006-05-32.html
http://www.redhat.com/support/errata/RHSA-2006-0539.html
http://www.securityfocus.com/archive/1/435033/100/0/threaded
http://www.securityfocus.com/bid/18108
http://www.vupen.com/english/advisories/2006/2075
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=178431 ExploitPatch
https://exchange.xforce.ibmcloud.com/vulnerabilities/26691
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10213
https://usn.ubuntu.com/778-1/

Track CVE-2006-2607 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2001-0559Paul vixie vixie cron vulnerabilitycrontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a l…EPSS 1.1%7.2CVE-1999-0769Paul vixie vixie cron vulnerabilityVixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.EPSS 0.80%7.2CVE-1999-0872Paul vixie vixie cron vulnerabilityBuffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.EPSS 0.36%7.2CVE-1999-0297Paul vixie vixie cron vulnerabilityBuffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.EPSS 0.40%4.6CVE-2001-0560Paul vixie vixie cron vulnerabilityBuffer overflow in Vixie cron 3.0.1-56 and earlier could allow a local attacker to gain additional privileges via a long username (> 20 characters).EPSS 0.51%3.7CVE-2000-1096Paul vixie vixie cron vulnerabilitycrontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the …EPSS 0.79%3.3CVE-2010-0424Fedorahosted cronie link following vulnerabilityThe edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of …EPSS 0.35%2.1CVE-2007-1856Paul vixie vixie cron vulnerabilityVixie Cron before 4.1-r10 on Gentoo Linux is installed with insecure permissions, which allows local users to cause a denial of service (cron failure…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2006-2607), CISA KEV, FIRST EPSS (scores of 2026-10-07). This page is refreshed as NVD updates the record.