V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2010-0293
DEB
Medium

The client logging functionality in chronyd in Chrony before 1.23.1 does not restrict the amount of memory used for storage of client infor…

CVSS
5.0
Medium
EPSS
0.03
p83
Published
2010-01-01
Updated
2010-01-01
Description

The client logging functionality in chronyd in Chrony before 1.23.1 does not restrict the amount of memory used for storage of client information, which allows remote attackers to cause a denial of service (memory consumption) via spoofed (1) NTP or (2) cmdmon packets.

Tags · CWE
CWE-399
Affected products
Chrony ≤ 1.23-pre1Chrony
CVSS vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Timeline
2010-01-01
Published
2010-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.027 · p83
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
chronyTracked
chronyTracked
chrony*Tracked
Source databases
DEB
CVE
UBU