CVE-2012-4503
Last modified
CVE-2012-4503 is a vulnerability of currently unknown severity. cmdmon.c in Chrony before 1.29 allows remote attackers to obtain potentially sensitive information from stack memory via vectors related to (1) an invalid subnet in a RPY_SUBNETS_ACCESSED command to the handle_subnets_accessed function or (2) a RPY_CLIENT_ACCESSES command to the handle_client_accesses function when client logging is disabled, which causes uninitialized data to be included in a reply.. EPSS estimates a 3.08% chance of exploitation in the next 30 days.
Description
cmdmon.c in Chrony before 1.29 allows remote attackers to obtain potentially sensitive information from stack memory via vectors related to (1) an invalid subnet in a RPY_SUBNETS_ACCESSED command to the handle_subnets_accessed function or (2) a RPY_CLIENT_ACCESSES command to the handle_client_accesses function when client logging is disabled, which causes uninitialized data to be included in a reply.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Tuxfamily | Chrony | <= 1.28 | — |
| Tuxfamily | Chrony | 1.0 | — |
| Tuxfamily | Chrony | 1.1 | — |
| Tuxfamily | Chrony | 1.18 | — |
| Tuxfamily | Chrony | 1.19 | — |
| Tuxfamily | Chrony | 1.19.99.1 | — |
| Tuxfamily | Chrony | 1.19.99.2 | — |
| Tuxfamily | Chrony | 1.19.99.3 | — |
| Tuxfamily | Chrony | 1.20 | — |
| Tuxfamily | Chrony | 1.21 | — |
| Tuxfamily | Chrony | 1.23 | — |
| Tuxfamily | Chrony | 1.23.1 | — |
| Tuxfamily | Chrony | 1.24 | — |
| Tuxfamily | Chrony | 1.25 | — |
| Tuxfamily | Chrony | 1.26 | — |
| Tuxfamily | Chrony | 1.27 | — |
| Tuxfamily | Chrony | 1.28 | Pre1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-4503?
How severe is CVE-2012-4503?
How do I fix CVE-2012-4503?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-4497Cross-site scripting (XSS) vulnerability in the "3 slide gal…
- CVE-2012-4498The Activism module 6.x-2.x before 6.x-2.1 for Drupal does n…
- CVE-2012-4499The contact formatter page in the Email Field module 6.x-1.x…
- CVE-2012-4500The Announcements module 6.x-1.x before 6.x-1.5 for Drupal a…
- CVE-2012-4501Citrix Cloud.com CloudStack, and Apache CloudStack pre-relea…
- CVE-2012-4502Multiple integer overflows in pktlength.c in Chrony before 1…
- CVE-2012-4504Stack-based buffer overflow in the url::get_pac function in …
- CVE-2012-4505Heap-based buffer overflow in the px_pac_reload function in …
- CVE-2012-4506Directory traversal vulnerability in gitolite 3.x before 3.1…
- CVE-2012-4507The strchr function in procmime.c in Claws Mail (aka claws-m…
- CVE-2012-4508Race condition in fs/ext4/extents.c in the Linux kernel befo…
- CVE-2012-4509Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2012-4503?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
