MGASA-2019-0157 - Updated cronie packages fix security vulnerabilities

Publication date: 12 May 2019
URL: https://advisories.mageia.org/MGASA-2019-0157.html
Type: security
Affected Mageia releases: 6
CVE: CVE-2019-9704,
     CVE-2019-9705

Updated cronie packages fix security vulnerabilities:

Cronie before 1.5.3 allows local users to cause a denial of service
(daemon crash) via a large crontab file because the calloc return value
is not checked (CVE-2019-9704).

Cronie before 1.5.3 allows local users to cause a denial of service
(memory consumption) via a large crontab file because an unlimited number
of lines is accepted (CVE-2019-9705).

References:
- https://bugs.mageia.org/show_bug.cgi?id=24579
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/6DU7HAUAQR4E4AEBPYLUV6FZ4PHKH6A2/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9704
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9705

SRPMS:
- 6/core/cronie-1.5.4-1.mga6

Mageia 2019-0157: cronie security update

Updated cronie packages fix security vulnerabilities: Cronie before 1.5.3 allows local users to cause a denial of service (daemon crash) via a large crontab file because the callo...

Summary

Updated cronie packages fix security vulnerabilities:
Cronie before 1.5.3 allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked (CVE-2019-9704).
Cronie before 1.5.3 allows local users to cause a denial of service (memory consumption) via a large crontab file because an unlimited number of lines is accepted (CVE-2019-9705).

References

- https://bugs.mageia.org/show_bug.cgi?id=24579

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/6DU7HAUAQR4E4AEBPYLUV6FZ4PHKH6A2/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9704

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9705

Resolution

MGASA-2019-0157 - Updated cronie packages fix security vulnerabilities

SRPMS

- 6/core/cronie-1.5.4-1.mga6

Severity
Publication date: 12 May 2019
URL: https://advisories.mageia.org/MGASA-2019-0157.html
Type: security
CVE: CVE-2019-9704, CVE-2019-9705

Related News