CVE-2012-6110: Bcron Project Bcron Exec

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

bcron-exec in bcron before 0.10 does not close file descriptors associated with temporary files when running a cron job, which allows local users to modify job files and send spam messages by accessing an open file descriptor.

Affected products

  • Bcron Project Bcron Exec: up to and including 0.09; version 0.04 only; version 0.05 only; version 0.06 only; version 0.07 only; version 0.08 only

Published 2014-09-29. Last modified 2026-06-16.