Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Mageia 6: 2019-0157 Moderate: Cronie Denial Of Service Issue

mageia
Calendar Grey May 12, 2019
Dist Mageia Esm H88
The newly revised cronie packages for Mageia mitigate security vulnerabilities, notably addressing Denial of Service threats stemming from unverified inputs.
Updated cronie packages fix security vulnerabilities: Cronie before 1.5.3 allows local users to cause a denial of service (daemon crash) via a large crontab file because the callo...

Summary

Updated cronie packages fix security vulnerabilities:
Cronie before 1.5.3 allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked (CVE-2019-9704).
Cronie before 1.5.3 allows local users to cause a denial of service (memory consumption) via a large crontab file because an unlimited number of lines is accepted (CVE-2019-9705).

References

- https://bugs.mageia.org/show_bug.cgi?id=24579

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/6DU7HAUAQR4E4AEBPYLUV6FZ4PHKH6A2/

- https://www.cve.org/CVERecord?id=CVE-2019-9704

- https://www.cve.org/CVERecord?id=CVE-2019-9705

Resolution

SRPMS

- 6/core/cronie-1.5.4-1.mga6

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 12 May 2019
URL: https://advisories.mageia.org/MGASA-2019-0157.html
Type: security
CVE: CVE-2019-9704, CVE-2019-9705

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here