Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-4502
HistoryNov 05, 2013 - 12:00 a.m.

CVE-2012-4502

2013-11-0500:00:00
ubuntu.com
ubuntu.com
15

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.013

Percentile

86.2%

Multiple integer overflows in pktlength.c in Chrony before 1.29 allow
remote attackers to cause a denial of service (crash) via a crafted (1)
REQ_SUBNETS_ACCESSED or (2) REQ_CLIENT_ACCESSES command request to the
PKL_CommandLength function or crafted (3) RPY_SUBNETS_ACCESSED, (4)
RPY_CLIENT_ACCESSES, (5) RPY_CLIENT_ACCESSES_BY_INDEX, or (6)
RPY_MANUAL_LIST command reply to the PKL_ReplyLength function, which
triggers an out-of-bounds read or buffer overflow. NOTE: versions 1.27 and
1.28 do not require authentication to exploit.

Bugs

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.013

Percentile

86.2%