Unchecked Return Value in cron (Debian package) - CVE-2019-9704
Published: May 11, 2022
Vulnerability identifier: #VU63055
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9704
CWE-ID: CWE-252
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to the calloc return value is not checked. A local user can create a large crontab file and crash the daemon.
Affected software
cron (Debian package)
cronie
cron (Ubuntu package)
Isolation Segment
VMware Tanzu Application Service for VMs
cflinuxfs3
Tanzu Greenplum for Kubernetes
Ubuntu
Fedora
VMware Tanzu Operations Manager
cronie
cron (Ubuntu package)
Isolation Segment
VMware Tanzu Application Service for VMs
cflinuxfs3
Tanzu Greenplum for Kubernetes
Ubuntu
Fedora
VMware Tanzu Operations Manager
How to mitigate CVE-2019-9704
Install updates from vendor's website.
cron (Debian package) - update to 3.0pl1-133
Isolation Segment - addressed in versions 2.7.45, 2.10.25, 2.11.14, 2.12.8
VMware Tanzu Application Service for VMs - addressed in versions 2.7.50, 2.10.32, 2.11.20, 2.12.13
cflinuxfs3 - addressed in versions 0.294.0, 0.295.0
Tanzu Greenplum for Kubernetes - update to 2.0.0
cronie - addressed in versions 1.5.3-1.fc29, 1.5.3-1.fc30, 1.5.4-1.fc29, 1.5.4-1.fc30
VMware Tanzu Operations Manager - addressed in versions 2.9.39, 2.10.40
cron (Ubuntu package) - addressed in versions 3.0pl1-128.1ubuntu1.2, 3.0pl1128ubuntu2+esm1
Isolation Segment - addressed in versions 2.7.45, 2.10.25, 2.11.14, 2.12.8
VMware Tanzu Application Service for VMs - addressed in versions 2.7.50, 2.10.32, 2.11.20, 2.12.13
cflinuxfs3 - addressed in versions 0.294.0, 0.295.0
Tanzu Greenplum for Kubernetes - update to 2.0.0
cronie - addressed in versions 1.5.3-1.fc29, 1.5.3-1.fc30, 1.5.4-1.fc29, 1.5.4-1.fc30
VMware Tanzu Operations Manager - addressed in versions 2.9.39, 2.10.40
cron (Ubuntu package) - addressed in versions 3.0pl1-128.1ubuntu1.2, 3.0pl1128ubuntu2+esm1
External References
- https://salsa.debian.org/debian/cron/commit/f2525567
- http://www.securityfocus.com/bid/107373
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6DU7HAUAQR4E4AEBPYLUV6FZ4PHKH6A2/
- https://lists.debian.org/debian-lts-announce/2019/03/msg00025.html
- https://lists.debian.org/debian-lts-announce/2021/10/msg00029.html
Related Security Bulletins
- Ubuntu update for cron
- Multiple vulnerabilities in cflinuxfs3
- Multiple vulnerabilities in cflinuxfs3
- Ubuntu update for cron
- VMware Tanzu products update for Cron
- VMware Tanzu products update for Cron
- Fedora 30 update for cronie
- Fedora 29 update for cronie
- Fedora 29 update for cronie
- Fedora 30 update for cronie