CVE-2019-9705: Medium severity cron vulnerability
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (memory consumption) via a large crontab file because an unlimited number of lines is accepted.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-9705?
CVE-2019-9705 has a severity level classified as high due to its potential to cause denial of service through memory consumption.
How do I fix CVE-2019-9705?
To fix CVE-2019-9705, update to the latest version of the Cron package that is patched against this vulnerability.
Who is affected by CVE-2019-9705?
CVE-2019-9705 affects users of Vixie Cron versions before 3.0pl1-133 on Debian and Fedora operating systems.
What kind of attack vector is involved in CVE-2019-9705?
CVE-2019-9705 can be exploited by local users who can create excessively large crontab files that lead to denial of service.
Is CVE-2019-9705 a critical vulnerability?
While CVE-2019-9705 is serious due to its denial of service potential, it is not classified as critical as it requires local user access.