Unchecked Return Value in cron (Debian package) - CVE-2019-9704

 

Unchecked Return Value in cron (Debian package) - CVE-2019-9704

Published: May 11, 2022


Vulnerability identifier: #VU63055
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9704
CWE-ID: CWE-252
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to the calloc return value is not checked. A local user can create a large crontab file and crash the daemon.


Affected software

cron (Debian package)
cronie
cron (Ubuntu package)
Isolation Segment
VMware Tanzu Application Service for VMs
cflinuxfs3
Tanzu Greenplum for Kubernetes
Ubuntu
Fedora
VMware Tanzu Operations Manager

How to mitigate CVE-2019-9704

Install updates from vendor's website.

cron (Debian package) - update to 3.0pl1-133
Isolation Segment - addressed in versions 2.7.45, 2.10.25, 2.11.14, 2.12.8
VMware Tanzu Application Service for VMs - addressed in versions 2.7.50, 2.10.32, 2.11.20, 2.12.13
cflinuxfs3 - addressed in versions 0.294.0, 0.295.0
Tanzu Greenplum for Kubernetes - update to 2.0.0
cronie - addressed in versions 1.5.3-1.fc29, 1.5.3-1.fc30, 1.5.4-1.fc29, 1.5.4-1.fc30
VMware Tanzu Operations Manager - addressed in versions 2.9.39, 2.10.40
cron (Ubuntu package) - addressed in versions 3.0pl1-128.1ubuntu1.2, 3.0pl1128ubuntu2+esm1

External References

Related Security Bulletins