Allocation of Resources Without Limits or Throttling in cron (Debian package) - CVE-2019-9705

 

Allocation of Resources Without Limits or Throttling in cron (Debian package) - CVE-2019-9705

Published: May 11, 2022


Vulnerability identifier: #VU63054
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9705
CWE-ID: CWE-770
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to Vixie Cron implementation allows unlimited number of lines to be inserted into the crontab file. A local user can create a very large crontab file and consume all available memory on the system.


Affected software

cron (Debian package)
cronie
cron (Ubuntu package)
Isolation Segment
VMware Tanzu Application Service for VMs
cflinuxfs3
Tanzu Greenplum for Kubernetes
Ubuntu
Fedora
VMware Tanzu Operations Manager

How to mitigate CVE-2019-9705

Install updates from vendor's website.

cron (Debian package) - update to 3.0pl1-133
Isolation Segment - addressed in versions 2.7.45, 2.10.25, 2.11.14, 2.12.8
VMware Tanzu Application Service for VMs - addressed in versions 2.7.50, 2.10.32, 2.11.20, 2.12.13
cflinuxfs3 - addressed in versions 0.294.0, 0.295.0
Tanzu Greenplum for Kubernetes - update to 2.0.0
cronie - addressed in versions 1.5.3-1.fc29, 1.5.3-1.fc30, 1.5.4-1.fc29, 1.5.4-1.fc30
VMware Tanzu Operations Manager - addressed in versions 2.9.39, 2.10.40
cron (Ubuntu package) - addressed in versions 3.0pl1-128.1ubuntu1.2, 3.0pl1128ubuntu2+esm1

External References

Related Security Bulletins