CVE-2006-0539

fcron 3.0.0 - Local Privilege Escalation via Long Command-Line Argument

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-0539. PoCs published by Adam Zabrocki.

AI-analyzed exploit summary The provided text describes a retired local buffer-overflow vulnerability in Fcron 3.0, which was initially believed to allow arbitrary code execution with superuser privileges. However, further analysis determined it was not exploitable for code execution.

Description

The convert-fcrontab program in fcron 3.0.0 might allow local users to gain privileges via a long command-line argument, which causes Linux glibc to report heap memory corruption, possibly because a strcpy in the strdup2 function can "overwrite some data."

Exploits (1)

exploitdb WRITEUP VERIFIED
by Adam Zabrocki · textdosmultiple
https://www.exploit-db.com/exploits/27159

The provided text describes a retired local buffer-overflow vulnerability in Fcron 3.0, which was initially believed to allow arbitrary code execution with superuser privileges. However, further analysis determined it was not exploitable for code execution.

Classification
Writeup 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: Fcron 3.0
Auth required
Prerequisites: local access to the system · Fcron installed with setuid-superuser privileges
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Various Sources x_refsource_confirm
http://fcron.free.fr/news.php#a20060206a.xml
Various Sources x_refsource_confirm
https://bugs.trustix.org/show_bug.cgi?id=1754
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/423697/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/24444
Third Party Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0999.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0435
Vendor Advisory vendor-advisory x_refsource_trustix
http://www.trustix.org/errata/2006/0036
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18719
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16467
Various Sources x_refsource_confirm
http://fcron.free.fr/doc/en/changes.html

Scores

EPSS 0.0076
EPSS Percentile 50.6%

Details

Status published
Products (1)
thibault_godouet/fcron 3.0.0
Published Feb 04, 2006
Tracked Since Feb 18, 2026