Hi Robert!
Yes, I know that cron is the most do not upgradable daemon in any unix system (so in FreeBSD cron didn't get opportunity to include another cron's configs, I've tried to send patch for add this, but in FreeBSD community I got refusing). I think that we have to remember the old classical software and try to upgrade it. And any big upgrade is growing from one small patch. May be it can bring some bugs in feature, but it's normal - only dead software hasn't bugs:) Many Debian's users are trying to find variants for change mail's header, but I think it isn't correct.
What we can break in this case? Is a buffer overflow? I try to use function with limited length for this. Yes, user can input some incorrect data for mail's subject, but it transfer via cron to exec call, and I think is the most problem that can be - is a crash of the mail program.
Please correct me if I wrong
---
Site Reliability Engineer
Stan E. Putrya
/"\
\ / ASCII Ribbon Campaign
X against HTML email & vCards
/ \