Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked.
The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cron | Cron_project | * | 3.0pl1-133 (excluding) |
Cron | Ubuntu | bionic | * |
Cron | Ubuntu | cosmic | * |
Cron | Ubuntu | disco | * |
Cron | Ubuntu | esm-infra-legacy/trusty | * |
Cron | Ubuntu | esm-infra/xenial | * |
Cron | Ubuntu | precise/esm | * |
Cron | Ubuntu | trusty | * |
Cron | Ubuntu | trusty/esm | * |
Cron | Ubuntu | upstream | * |
Cron | Ubuntu | xenial | * |