UBUNTU-CVE-2015-1821
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-1821
Summary:
Details: Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute arbitrary code by configuring the (1) NTP or (2) cmdmon access with a subnet size that is indivisible by four and an address with a nonzero bit in the subnet remainder.
References: https://ubuntu.com/security/CVE-2015-1821, http://git.tuxfamily.org/chrony/chrony.git/commit/?h=1.31-security&id=cf19042ecb656b8afec0cc4906e7dd3ea9266ac8, https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-1821, http://chrony.tuxfamily.org/News.html, https://www.cve.org/CVERecord?id=CVE-2015-1821
Affected packages
Package
Name: chrony
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
