CVE-2019-9706
Ubuntu Security Notice USN-5259-2
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (use-after-free and daemon crash) because of a force_rescan_user error.
Vixie Cron, en versiones anteriores a la 3.0pl1-133 en el paquete Debian, permite a los usuarios locales provocar una denegaciĆ³n de servicio (uso de memoria previamente liberada y cierre inesperado del demonio) debido a un error de force_rescan_user.
USN-5259-1 and USN-5259-2 fixed vulnerabilities in Cron. Unfortunately that update was incomplete and could introduce a regression. This update fixes the problem. It was discovered that the postinst maintainer script in Cron unsafely handled file permissions during package install or update operations. An attacker could possibly use this issue to perform a privilege escalation attack. Florian Weimer discovered that Cron incorrectly handled certain memory operations during crontab file creation. An attacker could possibly use this issue to cause a denial of service. It was discovered that Cron incorrectly handled user input during crontab file creation. An attacker could possibly use this issue to cause a denial of service. It was discovered that Cron contained a use-after-free vulnerability in its force_rescan_user function. An attacker could possibly use this issue to cause a denial of service.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-03-11 CVE Reserved
- 2019-03-12 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-416: Use After Free
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2019/03/msg00025.html | Mailing List |
|
https://lists.debian.org/debian-lts-announce/2021/10/msg00029.html | Mailing List |
|
URL | Date | SRC |
---|---|---|
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=809167 | 2024-08-04 |
URL | Date | SRC |
---|---|---|
https://packages.qa.debian.org/c/cron/news/20190311T170403Z.html | 2021-11-30 | |
https://salsa.debian.org/debian/cron/commit/40791b93 | 2021-11-30 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-100 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-101 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-102 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-103 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-104 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-105 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-106 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-107 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-108 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-109 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-110 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-111 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-112 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-113 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-114 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-115 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-116 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-117 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-118 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-119 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-120 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-121 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-122 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-123 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-124 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-124.1 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-124.2 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-125 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-126 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-127 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-128 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-130 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-131 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-132 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-37 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-38 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-39 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-40 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-41 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-42 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-43 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-44 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-45 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-46 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-47 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-48 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-49 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-50 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-50.1 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-50.2 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-51 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-53 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-54 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-55 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-56 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-57 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-57.2 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-57.3 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-58 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-59 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-60 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-61 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-62 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-63 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-64 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-65 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-66 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-67 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-68 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-69 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-70 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-71 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-72 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-73 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-74 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-75 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-76 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-77 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-78 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-79 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-80 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-81 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-82 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-83 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-84 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-85 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-86 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-87 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-88 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-89 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-90 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-91 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-92 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-93 |
Affected
| ||||||
Debian Search vendor "Debian" | Cron Search vendor "Debian" for product "Cron" | 3.0 Search vendor "Debian" for product "Cron" and version "3.0" | pl1-94 |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|