Bug 24579 - cronie new security issues CVE-2019-970[45]
Summary: cronie new security issues CVE-2019-970[45]
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA6-32-OK MGA6-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2019-03-28 21:03 CET by David Walser
Modified: 2019-05-12 11:36 CEST (History)
7 users (show)

See Also:
Source RPM: cronie-1.5.1-1.mga6.src.rpm
CVE:
Status comment: Fixed upstream in 1.5.3


Attachments

Description David Walser 2019-03-28 21:03:15 CET
Fedora has issued an advisory on March 21:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/6DU7HAUAQR4E4AEBPYLUV6FZ4PHKH6A2/

The issues are fixed upstream in 1.5.3 (regression fix in 1.5.4).
David Walser 2019-03-28 21:23:38 CET

Status comment: (none) => Fixed upstream in 1.5.3

Comment 1 Marja Van Waes 2019-03-29 07:57:59 CET
Assigning to our registered cronie maintainer.

CC: (none) => marja11
Assignee: bugsquad => shlomif

Comment 2 Shlomi Fish 2019-03-29 13:02:18 CET
submitted updated 1.5.2 pkg to core6/updates-testing.
Comment 3 David Walser 2019-03-29 14:35:18 CET
Advisory:
========================

Updated cronie packages fix security vulnerabilities:

Cronie before 1.5.3 allows local users to cause a denial of service (daemon
crash) via a large crontab file because the calloc return value is not checked
(CVE-2019-9704).

Cronie before 1.5.3 allows local users to cause a denial of service (memory
consumption) via a large crontab file because an unlimited number of lines is
accepted (CVE-2019-9705).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9704
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9705
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/6DU7HAUAQR4E4AEBPYLUV6FZ4PHKH6A2/
========================

Updated packages in core/updates_testing:
========================
cronie-1.5.4-1.mga6
cronie-anacron-1.5.4-1.mga6

from cronie-1.5.4-1.mga6.src.rpm

CC: (none) => shlomif
Assignee: shlomif => qa-bugs

Comment 4 Herman Viaene 2019-04-19 11:53:18 CEST
MGA6-32 MATE on IBM Thinkpad R50e
No installation issues.
# systemctl stop crond
# systemctl start crond
# systemctl -l status crond
● crond.service - Command Scheduler
   Loaded: loaded (/usr/lib/systemd/system/crond.service; enabled; vendor preset: enabled)
   Active: active (running) since vr 2019-04-19 11:43:12 CEST; 4s ago
 Main PID: 27108 (crond)
   CGroup: /system.slice/crond.service
           ├─19657 /usr/sbin/anacron -s
           └─27108 /usr/sbin/crond -n

apr 19 11:43:12 mach6.hviaene.thuis systemd[1]: Started Command Scheduler.
apr 19 11:43:12 mach6.hviaene.thuis crond[27108]: (CRON) STARTUP (1.5.4)
apr 19 11:43:12 mach6.hviaene.thuis crond[27108]: (CRON) INFO (RANDOM_DELAY will be scaled with fa
apr 19 11:43:12 mach6.hviaene.thuis crond[27108]: (CRON) INFO (running with inotify support)
apr 19 11:43:12 mach6.hviaene.thuis crond[27108]: (CRON) INFO (@reboot jobs will be run at compute
# anacron -V
Anacron from project cronie 1.5.4
Copyright (C) 1998  Itai Tzur <itzur@actcom.co.il>
Copyright (C) 1999  Sean 'Shaleh' Perry <shaleh@debian.org>
Copyright (C) 2004  Pascal Hakim <pasc@redellipse.net>

Mail comments, suggestions and bug reports to <pasc@redellipse.net>.

Looks OK

CC: (none) => herman.viaene
Whiteboard: (none) => MGA6-32-OK

Comment 5 PC LX 2019-04-28 11:34:31 CEST
Installed and tested without issue.

System: Mageia 6, x86_64, Intel CPU.

Seems to be working correctly, at least for the hourly cron jobs.



$ uname -a
Linux marte 4.14.106-desktop-1.mga6 #1 SMP Thu Mar 14 18:01:29 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
$ rpm -qa | grep cronie
cronie-anacron-1.5.4-1.mga6
cronie-1.5.4-1.mga6
$ systemctl status crond
● crond.service - Command Scheduler
   Loaded: loaded (/usr/lib/systemd/system/crond.service; enabled; vendor preset: enabled)
   Active: active (running) since Dom 2019-04-28 10:22:43 WEST; 2min 11s ago
 Main PID: 4983 (crond)
   CGroup: /system.slice/crond.service
           ├─4108 /usr/sbin/anacron -s
           ├─4120 /usr/lib64/sa/sadc -F -L 600 6 /var/log/sa
           └─4983 /usr/sbin/crond -n

Abr 28 10:22:43 marte crond[4983]: (CRON) STARTUP (1.5.4)
Abr 28 10:22:43 marte systemd[1]: Started Command Scheduler.
Abr 28 10:22:43 marte crond[4983]: (CRON) INFO (RANDOM_DELAY will be scaled with factor 53% if used.)
Abr 28 10:22:43 marte crond[4983]: (CRON) INFO (running with inotify support)
Abr 28 10:22:43 marte crond[4983]: (CRON) INFO (@reboot jobs will be run at computer's startup.)

CC: (none) => mageia
Whiteboard: MGA6-32-OK => MGA6-32-OK MGA6-64-OK

Comment 6 Thomas Andrews 2019-05-02 16:35:13 CEST
Looks good, then. Validating. Suggested advisory in Comment 3.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Thomas Backlund 2019-05-12 09:52:21 CEST

CC: (none) => tmb
Keywords: (none) => advisory

Comment 7 Mageia Robot 2019-05-12 11:36:58 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2019-0157.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.