Описание
Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute arbitrary code by configuring the (1) NTP or (2) cmdmon access with a subnet size that is indivisible by four and an address with a nonzero bit in the subnet remainder.
Релиз | Статус | Примечание |
---|---|---|
artful | not-affected | 3.1-5 |
bionic | not-affected | 3.2-4ubuntu1 |
cosmic | not-affected | 3.2-4ubuntu1 |
devel | not-affected | 3.2-4ubuntu1 |
esm-apps/xenial | not-affected | 2.1.1-1 |
esm-infra-legacy/trusty | released | 1.29-1ubuntu0.1 |
esm-infra/bionic | not-affected | 3.2-4ubuntu1 |
lucid | ignored | end of life |
precise | ignored | end of life |
precise/esm | DNE | precise was needed |
Показывать по
EPSS
6.5 Medium
CVSS2
Связанные уязвимости
Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute arbitrary code by configuring the (1) NTP or (2) cmdmon access with a subnet size that is indivisible by four and an address with a nonzero bit in the subnet remainder.
Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute arbitrary code by configuring the (1) NTP or (2) cmdmon access with a subnet size that is indivisible by four and an address with a nonzero bit in the subnet remainder.
Heap-based buffer overflow in chrony before 1.31.1 allows remote authe ...
Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute arbitrary code by configuring the (1) NTP or (2) cmdmon access with a subnet size that is indivisible by four and an address with a nonzero bit in the subnet remainder.
ELSA-2015-2241: chrony security, bug fix, and enhancement update (MODERATE)
EPSS
6.5 Medium
CVSS2