PT-2019-6250 · Isc+2 · Vixie Cron+2
Florian Weimer
·
Published
2019-03-10
·
Updated
2024-06-15
·
CVE-2019-9704
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Vixie Cron versions prior to 3.0pl1-133
Description
The issue is related to a daemon scheduler task vulnerability in UNIX-like operating systems, specifically in the Cron system. It involves pointer dereference errors. Exploitation of this issue allows an attacker to cause a denial of service, leading to a daemon crash. This can be achieved by a local user through a large crontab file, as the calloc return value is not properly checked.
Recommendations
For Vixie Cron versions prior to 3.0pl1-133, update to version 3.0pl1-133 or later to resolve the issue. As a temporary workaround, consider restricting access to large crontab files to minimize the risk of exploitation.
Fix
DoS
NULL Pointer Dereference
Unchecked Return Value
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse
Ubuntu
Vixie Cron