Mageia 2019-0157: cronie security update
Summary
Updated cronie packages fix security vulnerabilities:
Cronie before 1.5.3 allows local users to cause a denial of service
(daemon crash) via a large crontab file because the calloc return value
is not checked (CVE-2019-9704).
Cronie before 1.5.3 allows local users to cause a denial of service
(memory consumption) via a large crontab file because an unlimited number
of lines is accepted (CVE-2019-9705).
References
- https://bugs.mageia.org/show_bug.cgi?id=24579
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/6DU7HAUAQR4E4AEBPYLUV6FZ4PHKH6A2/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9704
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9705
Resolution
MGASA-2019-0157 - Updated cronie packages fix security vulnerabilities
SRPMS
- 6/core/cronie-1.5.4-1.mga6