Ubuntu Security Notice USN-5259-1 ≈ Packet Storm

Home[1] Files[2] News[3] Contact[4] Add New[5]

Ubuntu Security Notice USN-5259-1[6]
Authored by Ubuntu[7] | Site security.ubuntu.com[8]

Ubuntu Security Notice 5259-1 - It was discovered that the postinst maintainer script in Cron unsafely handled file permissions during package install or update operations. An attacker could possibly use this issue to perform a privilege escalation attack. Florian Weimer discovered that Cron incorrectly handled certain memory operations during crontab file creation. An attacker could possibly use this issue to cause a denial of service.

systems | linux[9], ubuntu[10]
advisories | CVE-2017-9525[11], CVE-2019-9704[12], CVE-2019-9705[13], CVE-2019-9706[14]
MD5 | af950739e60267b500aa26f7a50adb73

Change Mirror[18] Download[19]

        ==========================================================================
Ubuntu Security Notice USN-5259-1
February 01, 2022
cron vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 ESM
Summary:
Several security issues were fixed in Cron.
Software Description:
- cron: process scheduling daemon
Details:
It was discovered that the postinst maintainer script in Cron unsafely
handled file permissions during package install or update operations.
An attacker could possibly use this issue to perform a privilege
escalation attack. (CVE-2017-9525)
Florian Weimer discovered that Cron incorrectly handled certain memory
operations during crontab file creation. An attacker could possibly use
this issue to cause a denial of service. (CVE-2019-9704)
It was discovered that Cron incorrectly handled user input during crontab
file creation. An attacker could possibly use this issue to cause a denial
of service. (CVE-2019-9705)
It was discovered that Cron contained a use-after-free vulnerability in
its force_rescan_user function. An attacker could possibly use this issue
to cause a denial of service. (CVE-2019-9706)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 ESM:
cron 3.0pl1-128ubuntu2+esm1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5259-1
CVE-2017-9525, CVE-2019-9704, CVE-2019-9705, CVE-2019-9706

Login[20] or Register[21] to add favorites

File Archive:

February 2022

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa

File Tags

File Archives

Systems

packet storm

© 2020 Packet Storm. All rights reserved.

Services
Security Services[125]
Hosting By
Rokasec[126]
close

Read more

Image

Pensée du jour :

Ce que l'homme a fait ,

l'homme peut le défaire.

 

"No secure path in the world"