Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gf8j-j7q8-vhh5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.

chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.

EPSS

Процентиль: 75%
0.00915
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 6 лет назад

chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.

redhat
почти 11 лет назад

chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.

CVSS3: 6.5
nvd
около 6 лет назад

chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.

CVSS3: 6.5
debian
около 6 лет назад

chrony before 1.31.1 does not properly protect state variables in auth ...

oracle-oval
около 10 лет назад

ELSA-2015-2241: chrony security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 75%
0.00915
Низкий

6.5 Medium

CVSS3