USN-5259-3

Source
https://ubuntu.com/security/notices/USN-5259-3
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5259-3.json
JSON Data
https://api.osv.dev/v1/vulns/USN-5259-3
Related
Published
2022-05-11T00:25:41.666008Z
Modified
2022-05-11T00:25:41.666008Z
Summary
cron regression
Details

USN-5259-1 and USN-5259-2 fixed vulnerabilities in Cron. Unfortunately that update was incomplete and could introduce a regression. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

It was discovered that the postinst maintainer script in Cron unsafely handled file permissions during package install or update operations. An attacker could possibly use this issue to perform a privilege escalation attack. (CVE-2017-9525)

Florian Weimer discovered that Cron incorrectly handled certain memory operations during crontab file creation. An attacker could possibly use this issue to cause a denial of service. (CVE-2019-9704)

It was discovered that Cron incorrectly handled user input during crontab file creation. An attacker could possibly use this issue to cause a denial of service. (CVE-2019-9705)

It was discovered that Cron contained a use-after-free vulnerability in its forcerescanuser function. An attacker could possibly use this issue to cause a denial of service. (CVE-2019-9706)

References

Affected packages

Ubuntu:Pro:16.04:LTS / cron

Package

Name
cron
Purl
pkg:deb/ubuntu/cron@3.0pl1-128ubuntu2+esm2?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0pl1-128ubuntu2+esm2

Affected versions

3.*

3.0pl1-127ubuntu1
3.0pl1-128ubuntu1
3.0pl1-128ubuntu2
3.0pl1-128ubuntu2+esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "3.0pl1-128ubuntu2+esm2",
            "binary_name": "cron"
        },
        {
            "binary_version": "3.0pl1-128ubuntu2+esm2",
            "binary_name": "cron-dbgsym"
        }
    ]
}

Ubuntu:18.04:LTS / cron

Package

Name
cron
Purl
pkg:deb/ubuntu/cron@3.0pl1-128.1ubuntu1.2?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0pl1-128.1ubuntu1.2

Affected versions

3.*

3.0pl1-128ubuntu5
3.0pl1-128.1ubuntu1
3.0pl1-128.1ubuntu1.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "3.0pl1-128.1ubuntu1.2",
            "binary_name": "cron"
        },
        {
            "binary_version": "3.0pl1-128.1ubuntu1.2",
            "binary_name": "cron-dbgsym"
        }
    ]
}