Format string vulnerability in crontab for SCO OpenServer 5.0.5 and 5.0.6 allows local users to gain privileges via format string specifiers in the file name argument.
http://www.securityfocus.com/bid/4938
http://www.iss.net/security_center/static/9271.php