Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Red Hat: 1999-030-01 Critical: Vixie Cron Denial Of Service

debian
Calendar Grey December 13, 1999
Debian Logo
A new security bulletin from Red Hat highlights a critical denial of service vulnerability in Vixie cron, prompting users to upgrade without delay.
Red Hat has recently released a Security Advisory (RHSA-1999:030-01) covering a reverse denial of service bug in the vixie cron package. As user you could restart sendmail even if ...

Summary

Red Hat has recently released a Security Advisory (RHSA-1999:030-01)
covering a reverse denial of service bug in the vixie cron package.
As user you could restart sendmail even if the host should not receive
mail through the SMTP port.

Further investigation of Caldera and Debian discovered that it was
even worse. Red Hat did find a root exploit but didn' notice. When
sending a mail to the user Vixie Cron ran as root, not checking the
mail address that was passed to sendmail on the commandline.


We recommend you upgrade your cron package immediately.


wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.


Debian GNU/Linux 2.1 alias slink
--------------------------------

This version of Debian was released only for the Intel, the
Motorola 68xxx, the alpha and the Sun sparc architecture.

Source archives:


-50.2.diff.gz
MD5 checksum: 96a4b55e06127c4a6cf31ee511227adb
-
50.2.dsc
MD5 checksum: 3998735f00d3f10a5e290227db6bf611
.orig.ta
r.gz
...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here