Bug 1687706 (CVE-2019-9706) - CVE-2019-9706 vixie-cron: use-after-free resulting in dos
Summary: CVE-2019-9706 vixie-cron: use-after-free resulting in dos
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2019-9706
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1711927
Blocks: 1687709
TreeView+ depends on / blocked
 
Reported: 2019-03-12 07:56 UTC by Dhananjay Arunesh
Modified: 2019-09-29 15:08 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-06-10 10:50:28 UTC


Attachments (Terms of Use)

Description Dhananjay Arunesh 2019-03-12 07:56:59 UTC
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (use-after-free and daemon crash) because of a force_rescan_user error.

Reference:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=809167

Upstream commit:
https://salsa.debian.org/debian/cron/commit/40791b93

Comment 1 Tomas Mraz 2019-03-14 10:26:05 UTC
I do not think there is such code in cronie or the vixie-cron shipped in RHEL or Fedora.

Comment 2 Riccardo Schirone 2019-05-20 12:10:10 UTC
This seems to be caused by a downstream patch applied to Debian/Ubuntu and, as also said in comment 1, Fedora/RHEL are not affected by this flaw as they simply don't have the vulnerable code.

Comment 3 Riccardo Schirone 2019-05-20 12:21:36 UTC
Created cronie tracking bugs for this issue:

Affects: fedora-all [bug 1711927]

Comment 4 Riccardo Schirone 2019-05-20 12:25:10 UTC
Statement:

This issue did not affect the versions of vixie-cron as shipped with Red Hat Enterprise Linux 5 as they did not include the vulnerable code.
This issue did not affect the versions of cronie as shipped with Red Hat Enterprise Linux 6, 7, and 8 as they did not include the vulnerable code.


Note You need to log in before you can comment on or make changes to this bug.