Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1853

Опубликовано: 07 апр. 2015
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.

A denial of service flaw was found in the way chrony hosts that were peering with each other authenticated themselves before updating their internal state variables. An attacker could send packets to one peer host, which could cascade to other peers, and stop the synchronization process among the reached peers.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-345
https://bugzilla.redhat.com/show_bug.cgi?id=1209572chrony: authentication doesn't protect symmetric associations against DoS attacks

EPSS

Процентиль: 75%
0.00915
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.

CVSS3: 6.5
nvd
больше 5 лет назад

chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.

CVSS3: 6.5
debian
больше 5 лет назад

chrony before 1.31.1 does not properly protect state variables in auth ...

CVSS3: 6.5
github
больше 3 лет назад

chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.

oracle-oval
почти 10 лет назад

ELSA-2015-2241: chrony security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 75%
0.00915
Низкий

4.3 Medium

CVSS2