Use-after-free in cron (Debian package) - CVE-2019-9706

 

Use-after-free in cron (Debian package) - CVE-2019-9706

Published: May 11, 2022


Vulnerability identifier: #VU63053
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9706
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error in force_rescan_user() function in Vixie Cron. A local user can write specially crafted data to the crontab file, trigger a use-after-free error and crash the daemon.


Affected software

cron (Debian package)
cron (Ubuntu package)
Isolation Segment
VMware Tanzu Application Service for VMs
cflinuxfs3
Tanzu Greenplum for Kubernetes
Ubuntu
VMware Tanzu Operations Manager

How to mitigate CVE-2019-9706

Install updates from vendor's website.

cron (Debian package) - update to 3.0pl1-133
Isolation Segment - addressed in versions 2.7.45, 2.10.25, 2.11.14, 2.12.8
VMware Tanzu Application Service for VMs - addressed in versions 2.7.50, 2.10.32, 2.11.20, 2.12.13
cflinuxfs3 - addressed in versions 0.294.0, 0.295.0
Tanzu Greenplum for Kubernetes - update to 2.0.0
VMware Tanzu Operations Manager - addressed in versions 2.9.39, 2.10.40
cron (Ubuntu package) - addressed in versions 3.0pl1-128.1ubuntu1.2, 3.0pl1128ubuntu2+esm1

External References

Related Security Bulletins