Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-1822

Опубликовано: 16 апр. 2015
Источник: nvd
CVSS2: 6.5
EPSS Низкий

Описание

chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and daemon crash) or possibly execute arbitrary code via a large number of command requests.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:tuxfamily:chrony:*:*:*:*:*:*:*:*
Версия до 1.31 (включая)

EPSS

Процентиль: 83%
0.0211
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-17

Связанные уязвимости

ubuntu
больше 10 лет назад

chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and daemon crash) or possibly execute arbitrary code via a large number of command requests.

redhat
больше 10 лет назад

chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and daemon crash) or possibly execute arbitrary code via a large number of command requests.

debian
больше 10 лет назад

chrony before 1.31.1 does not initialize the last "next" pointer when ...

github
больше 3 лет назад

chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and daemon crash) or possibly execute arbitrary code via a large number of command requests.

oracle-oval
почти 10 лет назад

ELSA-2015-2241: chrony security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 83%
0.0211
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-17