CVE-2019-9706: Debian Cron

Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (use-after-free and daemon crash) because of a force_rescan_user error.

Affected products

  • Debian Cron: version 3.0 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only

Published 2019-03-12. Last modified 2026-06-17.