vixie-cron-4.1-81.AXS3

エラータID: AXSA:2012-254:01

Release date: 
Wednesday, March 7, 2012 - 21:47
Subject: 
vixie-cron-4.1-81.AXS3
Affected Channels: 
Asianux Server 3 for x86
Asianux Server 3 for x86_64
Severity: 
High
Description: 

The vixie-cron package contains the Vixie version of cron. Cron is a standard UNIX daemon that runs specified programs at scheduled times. Vixie cron adds better security and more powerful configuration options to the standard version of cron.
Security issues fixed with this release:
CVE-2010-0424
The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequently cause a denial of service, via a symlink attack on a temporary file in the /tmp directory.
Fixed bugs:
• A temporary NSS lookup failure often prevented the execution of cron jobs from users with home directories mounted on a LDAP server or NFS because such jobs would then be marked as orphaned. This update introduces the creation of a orphans database and cron jobs are performed as expected.
• Previously, cron did not log any errors if a cron job file located in the /etc/cron.d/ directory contained invalid entries. This has been fixed and invalid entries in the cron job files now produce warning messages.
• Previously, the @reboot crontab macro incorrectly ran jobs when the crond daemon was restarted. When used on several machines, all entries with the @reboot option were executed every time the crond daemon was restarted. This has been fixed and jobs are executed only when the machine is rebooted.
• crontab is now compiled as a position-independent executable (PIE), which enhances the security of the system.
• If the parent crond daemon was stopped but the a child daemon was still running, the service crond status command incorrectly reported that crond was running.This has been fixed and the service crond status command now correctly reports that crond is stopped.
• This update includes a corrected /etc/pam.d/crond file that exports environment variables correctly. Setting pam variables via cron now works as documented in the pam(8) manual page.
• Previously, if the crond daemon attempted to use the label modified by mcstrand and mcstransd was not running, crond used an incorrect label. Consequently, Security-Enhanced Linux (SELinux) denials filled up the cron log, no jobs were executed, and crond had to be restarted. This has been fixed by making mcstransd and crond use raw SELinux labels.
• Fixed many typos in the crontab(1) and cron(8) manual pages.
Enhancement:
• The crontab utility now uses Pluggable Authentication Module for user verification: it prevents users from accessing crontab, which was previously possible even if their access had been restricted. Crontab now returns an error message informing them that the PAM configuration prevents them from doing so.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. vixie-cron-4.1-81.AXS3.src.rpm
    MD5: 14c1a66c1655adb438bff88d5074a6ac
    SHA-256: e25333694445a84e3777a614a980a5f65952ad4d07c612d2e5fbade619464d1f
    Size: 152.92 kB

Asianux Server 3 for x86
  1. vixie-cron-4.1-81.AXS3.i386.rpm
    MD5: c6497e6a358f0524461c15169238b0a4
    SHA-256: 887afcef81397dfa0a0d60525094d9292105de3880e67a65b93a6b3413540982
    Size: 81.63 kB

Asianux Server 3 for x86_64
  1. vixie-cron-4.1-81.AXS3.x86_64.rpm
    MD5: 27ae8b9089ac286628ec694375dd6db8
    SHA-256: a63497631201a8d3a0de1eda5d5ebec7bdea8be9c95124ccf4698b8510a77cb0
    Size: 83.48 kB