Описание
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked.
A vulnerability was found in the Vixie Cron package, caused by improper validation of the return value from the calloc function. A local attacker could exploit this flaw by using a specially crafted crontab file, resulting in a denial of service condition and potentially crashing the service.
Отчет
This vulnerability was rated as LOW severity because it requires local access and a specially crafted crontab file to exploit. While it does not lead to system compromise, it can cause the cron service to crash temporarily
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | vixie-cron | Will not fix | ||
| Red Hat Enterprise Linux 6 | cronie | Out of support scope | ||
| Red Hat Enterprise Linux 7 | cronie | Will not fix | ||
| Red Hat Enterprise Linux 8 | cronie | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
3.3 Low
CVSS3
Связанные уязвимости
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked.
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked.
Vixie Cron before the 3.0pl1-133 Debian package allows local users to ...
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked.
Уязвимость демона-планировщика задач в UNIX-подобных операционных системах Cron, связанная с ошибками разыменования указателя, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
3.3 Low
CVSS3