bcron-exec in bcron before 0.10 does not close file descriptors associated with temporary files when running a cron job, which allows local users to modify job files and send spam messages by accessing an open file descriptor.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "0.09-13", "binary_name": "bcron" }, { "binary_version": "0.09-13", "binary_name": "bcron-run" } ] }