CVE Vulnerabilities

CVE-2010-0293

Published: Feb 08, 2010 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

The client logging functionality in chronyd in Chrony before 1.23.1 does not restrict the amount of memory used for storage of client information, which allows remote attackers to cause a denial of service (memory consumption) via spoofed (1) NTP or (2) cmdmon packets.

Affected Software

Name Vendor Start Version End Version
Chrony Tuxfamily * 1.23-pre1 (including)
Chrony Tuxfamily 1.18 (including) 1.18 (including)
Chrony Tuxfamily 1.19 (including) 1.19 (including)
Chrony Tuxfamily 1.19-1 (including) 1.19-1 (including)
Chrony Tuxfamily 1.19.99.1 (including) 1.19.99.1 (including)
Chrony Tuxfamily 1.19.99.2 (including) 1.19.99.2 (including)
Chrony Tuxfamily 1.19.99.3 (including) 1.19.99.3 (including)
Chrony Tuxfamily 1.20 (including) 1.20 (including)
Chrony Tuxfamily 1.21 (including) 1.21 (including)
Chrony Tuxfamily 1.21-pre1 (including) 1.21-pre1 (including)
Chrony Tuxfamily 1.24-pre1 (including) 1.24-pre1 (including)

References