CVE-2012-4503
05.11.2013, 21:55
cmdmon.c in Chrony before 1.29 allows remote attackers to obtain potentially sensitive information from stack memory via vectors related to (1) an invalid subnet in a RPY_SUBNETS_ACCESSED command to the handle_subnets_accessed function or (2) a RPY_CLIENT_ACCESSES command to the handle_client_accesses function when client logging is disabled, which causes uninitialized data to be included in a reply.Enginsight
Vendor | Product | Version |
---|---|---|
tuxfamily | chrony | 𝑥 ≤ 1.28 |
tuxfamily | chrony | 1.0 |
tuxfamily | chrony | 1.1 |
tuxfamily | chrony | 1.18 |
tuxfamily | chrony | 1.19 |
tuxfamily | chrony | 1.19.99.1 |
tuxfamily | chrony | 1.19.99.2 |
tuxfamily | chrony | 1.19.99.3 |
tuxfamily | chrony | 1.20 |
tuxfamily | chrony | 1.21 |
tuxfamily | chrony | 1.21:pre1 |
tuxfamily | chrony | 1.23 |
tuxfamily | chrony | 1.23:pre1 |
tuxfamily | chrony | 1.23.1 |
tuxfamily | chrony | 1.24 |
tuxfamily | chrony | 1.24:pre1 |
tuxfamily | chrony | 1.25 |
tuxfamily | chrony | 1.25:pre1 |
tuxfamily | chrony | 1.25:pre2 |
tuxfamily | chrony | 1.26 |
tuxfamily | chrony | 1.26:pre1 |
tuxfamily | chrony | 1.27 |
tuxfamily | chrony | 1.27:pre1 |
tuxfamily | chrony | 1.28:pre1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References