CVE-2010-0293

The client logging functionality in chronyd in Chrony before 1.23.1 does not restrict the amount of memory used for storage of client information, which allows remote attackers to cause a denial of service (memory consumption) via spoofed (1) NTP or (2) cmdmon packets.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:tuxfamily:chrony:*:*:*:*:*:*:*:*
cpe:2.3:a:tuxfamily:chrony:1.18:*:*:*:*:*:*:*
cpe:2.3:a:tuxfamily:chrony:1.19:*:*:*:*:*:*:*
cpe:2.3:a:tuxfamily:chrony:1.19-1:*:*:*:*:*:*:*
cpe:2.3:a:tuxfamily:chrony:1.19.99.1:*:*:*:*:*:*:*
cpe:2.3:a:tuxfamily:chrony:1.19.99.2:*:*:*:*:*:*:*
cpe:2.3:a:tuxfamily:chrony:1.19.99.3:*:*:*:*:*:*:*
cpe:2.3:a:tuxfamily:chrony:1.20:*:*:*:*:*:*:*
cpe:2.3:a:tuxfamily:chrony:1.21:*:*:*:*:*:*:*
cpe:2.3:a:tuxfamily:chrony:1.21-pre1:*:*:*:*:*:*:*
cpe:2.3:a:tuxfamily:chrony:1.24-pre1:*:*:*:*:*:*:*

History

07 Nov 2023, 02:05

Type Values Removed Values Added
References
  • {'url': 'http://git.tuxfamily.org/chrony/chrony.git/?p=gitroot/chrony/chrony.git;a=commit;h=2f63cf448560fdb96b80d8488aae6a15b802a753', 'name': 'http://git.tuxfamily.org/chrony/chrony.git/?p=gitroot/chrony/chrony.git;a=commit;h=2f63cf448560fdb96b80d8488aae6a15b802a753', 'tags': [], 'refsource': 'CONFIRM'}
  • () http://git.tuxfamily.org/chrony/chrony.git/?p=gitroot/chrony/chrony.git%3Ba=commit%3Bh=2f63cf448560fdb96b80d8488aae6a15b802a753 -

Information

Published : 2010-02-08 20:30

Updated : 2023-12-10 11:03


NVD link : CVE-2010-0293

Mitre link : CVE-2010-0293

CVE.ORG link : CVE-2010-0293


JSON object : View

Products Affected

tuxfamily

  • chrony
CWE
CWE-399

Resource Management Errors