Updated cronie packages fix security vulnerabilities:
Cronie before 1.5.3 allows local users to cause a denial of service
(daemon crash) via a large crontab file because the calloc return value
is not checked (CVE-2019-9704).
Cronie before 1.5.3 allows local users to cause a denial of service
(memory consumption) via a large crontab file because an unlimited number
of lines is accepted (CVE-2019-9705).
- https://bugs.mageia.org/show_bug.cgi?id=24579
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/6DU7HAUAQR4E4AEBPYLUV6FZ4PHKH6A2/
- https://www.cve.org/CVERecord?id=CVE-2019-9704
- https://www.cve.org/CVERecord?id=CVE-2019-9705
- 6/core/cronie-1.5.4-1.mga6
Get the latest Linux and open source security news straight to your inbox.