← Vulnerability feed

Vulnerability record · CVE-2007-1856 · published 18 April 2007

CVE-2007-1856: Paul vixie vixie cron vulnerability

PPaul Vixie · Vixie Cron

Vixie Cron before 4.1-r10 on Gentoo Linux is installed with insecure permissions, which allows local users to cause a denial of service (cron failure) by creating hard links, which results in a failed st_nlink check in database.c.

2.1 CVSS 2.0 Low EPSS 0.38% · top 70.0%
2.1CVSS 2.0 base score
0.38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
34References
16 Jun 2026Last modified by NVD

Description

Vixie Cron before 4.1-r10 on Gentoo Linux is installed with insecure permissions, which allows local users to cause a denial of service (cron failure) by creating hard links, which results in a failed st_nlink check in database.c.

AV:L/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html
http://rhn.redhat.com/errata/RHSA-2007-0345.html
http://secunia.com/advisories/24905
http://secunia.com/advisories/24995
http://secunia.com/advisories/25321
http://secunia.com/advisories/25723
http://secunia.com/advisories/26909
http://secunia.com/advisories/27706
http://secunia.com/advisories/27886
http://security.gentoo.org/glsa/glsa-200704-11.xml
http://support.avaya.com/elmodocs2/security/ASA-2007-261.htm
http://www.mandriva.com/security/advisories?name=MDKSA-2007:234
http://www.novell.com/linux/security/advisories/2007_007_suse.html
http://www.securityfocus.com/bid/23520
http://www.securitytracker.com/id?1018081
http://www.vupen.com/english/advisories/2007/3229
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11463
http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html
http://rhn.redhat.com/errata/RHSA-2007-0345.html
http://secunia.com/advisories/24905
http://secunia.com/advisories/24995
http://secunia.com/advisories/25321
http://secunia.com/advisories/25723
http://secunia.com/advisories/26909
http://secunia.com/advisories/27706
http://secunia.com/advisories/27886
http://security.gentoo.org/glsa/glsa-200704-11.xml
http://support.avaya.com/elmodocs2/security/ASA-2007-261.htm
http://www.mandriva.com/security/advisories?name=MDKSA-2007:234
http://www.novell.com/linux/security/advisories/2007_007_suse.html
http://www.securityfocus.com/bid/23520
http://www.securitytracker.com/id?1018081
http://www.vupen.com/english/advisories/2007/3229
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11463

Track CVE-2007-1856 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2006-2607Paul vixie vixie cron vulnerabilitydo_command.c in Vixie cron (vixie-cron) 4.1 does not check the return code of a setuid call, which might allow local users to gain root privileges if…EPSS 0.57%7.2CVE-2001-0559Paul vixie vixie cron vulnerabilitycrontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a l…EPSS 1.1%7.2CVE-1999-0769Paul vixie vixie cron vulnerabilityVixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.EPSS 0.80%7.2CVE-1999-0872Paul vixie vixie cron vulnerabilityBuffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.EPSS 0.36%7.2CVE-1999-0297Paul vixie vixie cron vulnerabilityBuffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.EPSS 0.40%4.6CVE-2001-0560Paul vixie vixie cron vulnerabilityBuffer overflow in Vixie cron 3.0.1-56 and earlier could allow a local attacker to gain additional privileges via a long username (> 20 characters).EPSS 0.51%3.7CVE-2000-1096Paul vixie vixie cron vulnerabilitycrontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the …EPSS 0.79%3.3CVE-2010-0424Fedorahosted cronie link following vulnerabilityThe edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of …EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2007-1856), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.