A "minor" bug in cron was reported in the Debian BTS:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144850
"cron: crontab(1) silently truncates file path arguments >=100 chars"
I suspect that there is a typo in the given instructions there
because the total number of characters is incorrect. Moreover,
the truncation is not silent, unless the file exists, in which
case it leads to a different crontab file being loaded, possibly
belonging to another user of the machine. So this is actually a
vulnerability, with possible execution of code from another user.
Under Debian with the cron 3.0pl1-210 package:
$
a=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
$ mkdir /tmp/${a}b
$ echo '* * * * * true' > /tmp/${a}b/x
$ echo '* * * * * false' > /tmp/${a}
$ crontab /tmp/${a}b/x
$ crontab -l
* * * * * false
(also reproducible with root creating /tmp/${a}b/x (actually not used)
and running "crontab /tmp/${a}b/x").
--
Vincent Lefèvre <[email protected]> - Web: <https://www.vinc17.net/>
100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/>
Work: CR INRIA - computer arithmetic / Pascaline project (LIP, ENS-Lyon)