Back to search
CVE-2015-1822
Published: Apr 16, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and daemon crash) or possibly execute arbitrary code via a large number of command requests.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
DSA-3222
vendor-advisory
x_refsource_DEBIAN
[chrony-announce] 20150407 chrony-1.31.1 released (security)
mailing-list
x_refsource_MLIST
GLSA-201507-01
vendor-advisory
x_refsource_GENTOO
73956
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now