CVE-2010-0293
Last modified
CVE-2010-0293 is a vulnerability of currently unknown severity. The client logging functionality in chronyd in Chrony before 1.23.1 does not restrict the amount of memory used for storage of client information, which allows remote attackers to cause a denial of service (memory consumption) via spoofed (1) NTP or (2) cmdmon packets.. EPSS estimates a 2.70% chance of exploitation in the next 30 days.
Description
The client logging functionality in chronyd in Chrony before 1.23.1 does not restrict the amount of memory used for storage of client information, which allows remote attackers to cause a denial of service (memory consumption) via spoofed (1) NTP or (2) cmdmon packets.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tuxfamily | Chrony | <= 1.23-pre1 |
| Tuxfamily | Chrony | 1.18 |
| Tuxfamily | Chrony | 1.19 |
| Tuxfamily | Chrony | 1.19-1 |
| Tuxfamily | Chrony | 1.19.99.1 |
| Tuxfamily | Chrony | 1.19.99.2 |
| Tuxfamily | Chrony | 1.19.99.3 |
| Tuxfamily | Chrony | 1.20 |
| Tuxfamily | Chrony | 1.21 |
| Tuxfamily | Chrony | 1.21-pre1 |
| Tuxfamily | Chrony | 1.24-pre1 |
References
- http://chrony.tuxfamily.org/News.htmlVendor Advisory
- http://secunia.com/advisories/38428Vendor Advisory
- http://secunia.com/advisories/38480Vendor Advisory
- http://chrony.tuxfamily.org/News.htmlVendor Advisory
- http://secunia.com/advisories/38428Vendor Advisory
- http://secunia.com/advisories/38480Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-0293?
How severe is CVE-2010-0293?
How do I fix CVE-2010-0293?
Are you affected by CVE-2010-0293?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
