Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
217

Enterprise Linux 4 ELSA-2007-0345 Moderate: Vixie Cron Denial Of Service

The following updated rpms for Enterprise Linux 4 have been uploaded to the Unbreakable Linux Network: . Enterprise Linux Security Advisory ELSA-2007-0345 https://access.redhat.com/errata/RHSA-2007:0345.html The following updated rpms for Enterprise Linux 4 have been uploaded to the Unbreakable Linux Network: i386: vixie-cron-4.1-47.EL4.i386.rpm x86_64: vixie-cron-4.1-47.EL4.x86_64.rpm SRPMS: https://oss.oracle.com:443/el4/SRPMS-updates/vixie-cron-4.1-47.EL4.src.rpm Description of changes: [4.1-47.EL4] - removed patches for 192783, 178836 because of frozen errata - added only patch for CVE-2007-1856 crontab denial of service - Resolves: rhbz#235880 [4.1-46.EL4] - Resolves: #235880 CVE-2007-1856 crontab denial of service [4.1-45.EL4] - rhbz#192783 - rhbz#178836 . The Enterprise Linux Security Announcement ELSA-2007-0345 outlines an update aimed at vixie cron, intended to mitigate a denial of service vulnerability.. Enterprise Linux,Vixie Cron,Security Advisory,Denial Of Service. . LinuxSecurity.com Team

Calendar%202 May 17, 2007 Oracle
91

Gentoo: GLSA-202103-09 Critical: Vixie Cron Security Flaw

Vixie Cron allows local users to execute programs as root.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200606-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Vixie Cron: Privilege Escalation Date: June 09, 2006 Bugs: #134194 ID: 200606-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Vixie Cron allows local users to execute programs as root. Background ========= Vixie Cron is a command scheduler with extended syntax over cron. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-process/vixie-cron < 4.1-r9 > = 4.1-r9 Description ========== Roman Veretelnikov discovered that Vixie Cron fails to properly check whether it can drop privileges accordingly if setuid() in do_command.c fails due to a user exceeding assigned resource limits. Impact ===== Local users can execute code with root privileges by deliberately exceeding their assigned resource limits and then starting a command through Vixie Cron. This requires resource limits to be in place on the machine. Workaround ========= There is no known workaround at this time. Resolution ========= All Vixie Cron users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-process/vixie-cron-4.1-r9" References ========= [ 1 ] CVE-2006-2607 https://www.cve.org/CVERecord?id=CVE-2006-2607 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200606-07 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo Linux Security Announcement GLSA 201906-10 highlights the OpenSSL security flaw which poses a critical threat.. Privilege Escalation,Gentoo Security,Vixie Cron,High Severity. . LinuxSecurity.com Team

Calendar%202 Jun 09, 2006 Gentoo
89

Fedora Core 3: Enhancements and Minor Fixes for vixie-cron Tool

Updated package released.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-550 2005-07-12 ---------------------------------------------------------------------Product : Fedora Core 3 Name : vixie-cron Version : 4.1 Release : 36.FC3 Summary : The Vixie cron daemon for executing specified programs at set times. Description : The vixie-cron package contains the Vixie version of cron. Cron is a standard UNIX daemon that runs specified programs at scheduled times. Vixie cron adds better security and more powerful configuration options to the standard version of cron. ---------------------------------------------------------------------Update Information: - fix bug 162887: allow multiple /etc/cron.d crontabs for *system* user - further fix for bug 154920 / CAN-2005-1038 ( crontab -e ): invoke editor and copy operation as non-root user ---------------------------------------------------------------------* Mon Jul 11 2005 Jason Vas Dias - 4.1-36.FC3 - fix bug 162887: allow multiple /etc/cron.d crontabs for *system* user - further fix for bug 154920 / CAN-2005-1038 ( crontab -e ): invoke editor and copy operation as non-root user - fix bug 160811: FC3 version compared > = FC4 version ---------------------------------------------------------------------This update can be downloaded from: 4a9fab23c95a42cbfab6826da467dd9e SRPMS/vixie-cron-4.1-36.FC3.src.rpm 066fda9ad1b88913a439a43db1db5ff2 x86_64/vixie-cron-4.1-36.FC3.x86_64.rpm 288bc505eb47611dc100fc916e003574 x86_64/debug/vixie-cron-debuginfo-4.1-36.FC3.x86_64.rpm 6ebbce985d0f6ded53fbb73c17b8f268 i386/vixie-cron-4.1-36.FC3.i386.rpm e220e2e902d1af9dec1fbd8862f9b0ca i386/debug/vixie-cron-debuginfo-4.1-36.FC3.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The CentOS 7 cronie package update addresses several vulnerabilities to enhance both performance and reliability for end users.. vixie-cron update,Fedora Core 3,scheduled tasks,bug fixes,cron daemon. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 12, 2005 Important Fedora
87

Red Hat: 1999-030-01 Critical: Vixie Cron Denial Of Service

Red Hat has recently released a Security Advisory (RHSA-1999:030-01) covering a reverse denial of service bug in the vixie cron package. As user you could restart sendmail even if the host should not receive mail through the SMTP port. . ---------------------------------------------------------------------------- Debian Security Advisory This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze August 30, 1999 ---------------------------------------------------------------------------- Red Hat has recently released a Security Advisory (RHSA-1999:030-01) covering a reverse denial of service bug in the vixie cron package. As user you could restart sendmail even if the host should not receive mail through the SMTP port. Further investigation of Caldera and Debian discovered that it was even worse. Red Hat did find a root exploit but didn' notice. When sending a mail to the user Vixie Cron ran as root, not checking the mail address that was passed to sendmail on the commandline. We recommend you upgrade your cron package immediately. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. Debian GNU/Linux 2.1 alias slink -------------------------------- This version of Debian was released only for the Intel, the Motorola 68xxx, the alpha and the Sun sparc architecture. Source archives: -50.2.diff.gz MD5 checksum: 96a4b55e06127c4a6cf31ee511227adb - 50.2.dsc MD5 checksum: 3998735f00d3f10a5e290227db6bf611 .orig.ta r.gz MD5 checksum: 4c64aece846f8483daf440f8e3dd210f Alpha architecture: alpha/cron_3.0pl1-50.2_alpha.deb MD5 checksum: cbab162fffd7dba71373b3eb62201b52 Intel ia32 architecture: i386/cron_3.0pl1-50.2_i386.deb MD5 checksum: 85d9ffff103d0121101b7b80817d0abe Motorola 680x0 architecture: m68k/cron_3.0pl1-50.2_m68k.deb MD5 checksum: 62a039991c237a92c4a3cdcef4a328d7 Sun Sparc architecture: sparc/cron_3.0pl1-50.2_sparc.deb MD5 checksum: 56f5e099ab621572b560706e1eec9ebb Debian GNU/Linux pre2.2 alias potato ------------------------------------ Source archives: -52.diff.gz MD5 checksum: f500a0dc7175d64de4822f159a51d739 52.dsc MD5 checksum: 1a16af335a106805ecdd6585a75ee61a g.tar.gz MD5 checksum: 4c64aece846f8483daf440f8e3dd210f Alpha architecture: alpha/cron_3.0pl1-52_alpha.deb MD5 checksum: 8e5246a79269b8f489a3cdb7efc41661 ARM architecture: arm/cron_3.0pl1-52_arm.deb MD5 checksum: 8d103d4a60ec94d1f0fb07caabd34575 Intel ia32 architecture: i386/cron_3.0pl1-52_i386.deb MD5 checksum: a7f8de4f43aa21e2fe94fe602c6c2c83 Motorola 680x0 architecture: m68k/cron_3.0pl1-52_m68k.deb MD5 checksum: b2e866ecc10e95094202327eab5fc0fd PowerPC architecture: powerpc/cron_3.0pl1-52_powerpc.deb MD5 checksum: 058a25564bc7c9c6fb153eafa0126cee Sun Sparc architecture: sparc/cron_3.0pl1-52_sparc.deb MD5 checksum: ed34f37c41d9322ba094ede04d8d2e16 For not yet released architectures please refer to the appropriate directory . ---------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable updates For dpkg-ftp: dists/stable/updates Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A new security bulletin from Red Hat highlights a critical denial of service vulnerability in Vixie cron, prompting users to upgrade without delay.. Red Hat Advisory, Vixie Cron Fix, Security Update, Denial of Service Bug. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 13, 1999 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200