Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gf8j-j7q8-vhh5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.

chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.

EPSS

Процентиль: 75%
0.00915
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.

redhat
больше 10 лет назад

chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.

CVSS3: 6.5
nvd
больше 5 лет назад

chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.

CVSS3: 6.5
debian
больше 5 лет назад

chrony before 1.31.1 does not properly protect state variables in auth ...

oracle-oval
почти 10 лет назад

ELSA-2015-2241: chrony security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 75%
0.00915
Низкий

6.5 Medium

CVSS3