← Vulnerability feed

Vulnerability record · CVE-2010-0424 · published 25 February 2010

CVE-2010-0424: Fedorahosted cronie link following vulnerability

Fedorahosted · Cronie

The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequently cause a denial of service, via a symlink attack on a temporary file in the /tmp directory.

3.3 CVSS 2.0 Low EPSS 0.35% · top 74.0% CWE-59 · Link following
3.3CVSS 2.0 base score
0.35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequently cause a denial of service, via a symlink attack on a temporary file in the /tmp directory.

AV:L/AC:M/Au:N/C:N/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-0424 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2006-2607Paul vixie vixie cron vulnerabilitydo_command.c in Vixie cron (vixie-cron) 4.1 does not check the return code of a setuid call, which might allow local users to gain root privileges if…EPSS 0.57%7.2CVE-2001-0559Paul vixie vixie cron vulnerabilitycrontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a l…EPSS 1.1%7.2CVE-1999-0769Paul vixie vixie cron vulnerabilityVixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.EPSS 0.80%7.2CVE-1999-0872Paul vixie vixie cron vulnerabilityBuffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.EPSS 0.36%7.2CVE-1999-0297Paul vixie vixie cron vulnerabilityBuffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.EPSS 0.40%4.6CVE-2001-0560Paul vixie vixie cron vulnerabilityBuffer overflow in Vixie cron 3.0.1-56 and earlier could allow a local attacker to gain additional privileges via a long username (> 20 characters).EPSS 0.51%4.3CVE-2012-6097Fedorahosted cronie information exposure vulnerabilityFile descriptor leak in cronie 1.4.8, when running in certain environments, might allow local users to read restricted files, as demonstrated by read…EPSS 1.3%3.7CVE-2000-1096Paul vixie vixie cron vulnerabilitycrontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the …EPSS 0.79%

Source: NIST National Vulnerability Database (record CVE-2010-0424), CISA KEV, FIRST EPSS (scores of 2026-10-07). This page is refreshed as NVD updates the record.