Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
The following updated rpms for Enterprise Linux 4 have been uploaded to the Unbreakable Linux Network: . Enterprise Linux Security Advisory ELSA-2007-0345 https://access.redhat.com/errata/RHSA-2007:0345.html The following updated rpms for Enterprise Linux 4 have been uploaded to the Unbreakable Linux Network: i386: vixie-cron-4.1-47.EL4.i386.rpm x86_64: vixie-cron-4.1-47.EL4.x86_64.rpm SRPMS: https://oss.oracle.com:443/el4/SRPMS-updates/vixie-cron-4.1-47.EL4.src.rpm Description of changes: [4.1-47.EL4] - removed patches for 192783, 178836 because of frozen errata - added only patch for CVE-2007-1856 crontab denial of service - Resolves: rhbz#235880 [4.1-46.EL4] - Resolves: #235880 CVE-2007-1856 crontab denial of service [4.1-45.EL4] - rhbz#192783 - rhbz#178836 . The Enterprise Linux Security Announcement ELSA-2007-0345 outlines an update aimed at vixie cron, intended to mitigate a denial of service vulnerability.. Enterprise Linux,Vixie Cron,Security Advisory,Denial Of Service. . LinuxSecurity.com Team
Vixie Cron allows local users to execute programs as root.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200606-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Vixie Cron: Privilege Escalation Date: June 09, 2006 Bugs: #134194 ID: 200606-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Vixie Cron allows local users to execute programs as root. Background ========= Vixie Cron is a command scheduler with extended syntax over cron. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-process/vixie-cron < 4.1-r9 > = 4.1-r9 Description ========== Roman Veretelnikov discovered that Vixie Cron fails to properly check whether it can drop privileges accordingly if setuid() in do_command.c fails due to a user exceeding assigned resource limits. Impact ===== Local users can execute code with root privileges by deliberately exceeding their assigned resource limits and then starting a command through Vixie Cron. This requires resource limits to be in place on the machine. Workaround ========= There is no known workaround at this time. Resolution ========= All Vixie Cron users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-process/vixie-cron-4.1-r9" References ========= [ 1 ] CVE-2006-2607 https://www.cve.org/CVERecord?id=CVE-2006-2607 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200606-07 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Updated package released.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-550 2005-07-12 ---------------------------------------------------------------------Product : Fedora Core 3 Name : vixie-cron Version : 4.1 Release : 36.FC3 Summary : The Vixie cron daemon for executing specified programs at set times. Description : The vixie-cron package contains the Vixie version of cron. Cron is a standard UNIX daemon that runs specified programs at scheduled times. Vixie cron adds better security and more powerful configuration options to the standard version of cron. ---------------------------------------------------------------------Update Information: - fix bug 162887: allow multiple /etc/cron.d crontabs for *system* user - further fix for bug 154920 / CAN-2005-1038 ( crontab -e ): invoke editor and copy operation as non-root user ---------------------------------------------------------------------* Mon Jul 11 2005 Jason Vas Dias - 4.1-36.FC3 - fix bug 162887: allow multiple /etc/cron.d crontabs for *system* user - further fix for bug 154920 / CAN-2005-1038 ( crontab -e ): invoke editor and copy operation as non-root user - fix bug 160811: FC3 version compared > = FC4 version ---------------------------------------------------------------------This update can be downloaded from: 4a9fab23c95a42cbfab6826da467dd9e SRPMS/vixie-cron-4.1-36.FC3.src.rpm 066fda9ad1b88913a439a43db1db5ff2 x86_64/vixie-cron-4.1-36.FC3.x86_64.rpm 288bc505eb47611dc100fc916e003574 x86_64/debug/vixie-cron-debuginfo-4.1-36.FC3.x86_64.rpm 6ebbce985d0f6ded53fbb73c17b8f268 i386/vixie-cron-4.1-36.FC3.i386.rpm e220e2e902d1af9dec1fbd8862f9b0ca i386/debug/vixie-cron-debuginfo-4.1-36.FC3.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Red Hat has recently released a Security Advisory (RHSA-1999:030-01) covering a reverse denial of service bug in the vixie cron package. As user you could restart sendmail even if the host should not receive mail through the SMTP port. . ---------------------------------------------------------------------------- Debian Security Advisory
Get the latest Linux and open source security news straight to your inbox.