← Back

CVE-2012-4502

nvd nist
Published: Nov 5, 2013Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Multiple integer overflows in pktlength.c in Chrony before 1.29 allow remote attackers to cause a denial of service (crash) via a crafted (1) REQ_SUBNETS_ACCESSED or (2) REQ_CLIENT_ACCESSES command request to the PKL_CommandLength function or crafted (3) RPY_SUBNETS_ACCESSED, (4) RPY_CLIENT_ACCESSES, (5) RPY_CLIENT_ACCESSES_BY_INDEX, or (6) RPY_MANUAL_LIST command reply to the PKL_ReplyLength function, which triggers an out-of-bounds read or buffer overflow. NOTE: versions 1.27 and 1.28 do not require authentication to exploit.

Affected (24)

Products: Tuxfamily: Chrony
1 product
Chrony
Configuration A
24 vulnerable
Vulnerable SoftwareAffected Versions
Tuxfamily
Up to 1.28
Version 1.0
Version 1.18
Version 1.19.99.1
Version 1.19.99.2
Version 1.19.99.3
Version 1.19
Version 1.1
Version 1.20
Version 1.21
Version 1.21 pre1
Version 1.23.1
Version 1.23
Version 1.23 pre1
Version 1.24
Version 1.24 pre1
Version 1.25
Version 1.25 pre1
Version 1.25 pre2
Version 1.26
Version 1.26 pre1
Version 1.27
Version 1.27 pre1
Version 1.28 pre1

Related CWEs

References (10)

Timeline

No history available yet.