188
VMScore

CVE-2019-9704

Published: 12/03/2019 Updated: 07/11/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 188
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

It exists that the postinst maintainer script in Cron unsafely handled file permissions during package install or update operations. An attacker could possibly use this issue to perform a privilege escalation attack. (CVE-2017-9525)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cron project cron

fedoraproject fedora 29

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

Several security issues were fixed in Cron ...
USN-5259-1 and USN-5259-2 introduced a regression in Cron ...
Several security issues were fixed in Cron ...
Impact: Low Public Date: 2019-03-08 CWE: CWE-400 Bugzilla: 1687688: CVE-2019-9704 vixie-cron: calloc re ...

Github Repositories

Debian CVE Scanner is self-contained CVE scanner for DEBIAN distributions written in golang.

Debian CVE Scanner The following project checks the installed packages of your Debian Linux distribution against known vulnerabilities of the Debian Security Bug Tracker security-trackerdebianorg/tracker Motivation The target of this project is to provider the CVE security scanning solution that is lightweight and self-contained The current standard solutio

Cronie cron daemon project

Cronie Cronie contains the standard UNIX daemon crond that runs specified programs at scheduled times and related tools The source is based on the original vixie-cron and has security and configuration enhancements like the ability to use pam and SELinux And why cronie? [wwwurbandictionarycom/definephp?term=cronie] Download Latest released version is 171 User vis