CVE-2012-4503
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
cmdmon.c in Chrony before 1.29 allows remote attackers to obtain potentially sensitive information from stack memory via vectors related to (1) an invalid subnet in a RPY_SUBNETS_ACCESSED command to the handle_subnets_accessed function or (2) a RPY_CLIENT_ACCESSES command to the handle_client_accesses function when client logging is disabled, which causes uninitialized data to be included in a reply.
cmdmon.c en Chrony antes de 1.29 permite a atacantes remotos obtener información sensible de la pila de memoria a través de vectores relacionados con (1) una subred no válida en un comando RPY_SUBNETS_ACCESSED a la función handle_subnets_accessed o (2) un comando RPY_CLIENT_ACCESSES para la función handle_client_accesses cuando el inicio de sesión de cliente está desactivado, lo causa que datos no inicializados se incluyan en la respuesta.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-08-21 CVE Reserved
- 2013-09-18 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://git.tuxfamily.org/chrony/chrony.git/?p=chrony/chrony.git%3Ba=commitdiff%3Bh=c6fdeeb6bb0b17dc28c19ae492c4a1c498e54ea3 | X_refsource_confirm | |
https://bugzilla.redhat.com/show_bug.cgi?id=846392 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://seclists.org/oss-sec/2013/q3/332 | 2023-11-07 |
URL | Date | SRC |
---|---|---|
http://permalink.gmane.org/gmane.comp.time.chrony.announce/15 | 2023-11-07 | |
http://www.debian.org/security/2013/dsa-2760 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | <= 1.28 Search vendor "Tuxfamily" for product "Chrony" and version " <= 1.28" | - |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.0 Search vendor "Tuxfamily" for product "Chrony" and version "1.0" | - |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.1 Search vendor "Tuxfamily" for product "Chrony" and version "1.1" | - |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.18 Search vendor "Tuxfamily" for product "Chrony" and version "1.18" | - |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.19 Search vendor "Tuxfamily" for product "Chrony" and version "1.19" | - |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.19.99.1 Search vendor "Tuxfamily" for product "Chrony" and version "1.19.99.1" | - |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.19.99.2 Search vendor "Tuxfamily" for product "Chrony" and version "1.19.99.2" | - |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.19.99.3 Search vendor "Tuxfamily" for product "Chrony" and version "1.19.99.3" | - |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.20 Search vendor "Tuxfamily" for product "Chrony" and version "1.20" | - |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.21 Search vendor "Tuxfamily" for product "Chrony" and version "1.21" | - |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.21 Search vendor "Tuxfamily" for product "Chrony" and version "1.21" | pre1 |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.23 Search vendor "Tuxfamily" for product "Chrony" and version "1.23" | - |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.23 Search vendor "Tuxfamily" for product "Chrony" and version "1.23" | pre1 |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.23.1 Search vendor "Tuxfamily" for product "Chrony" and version "1.23.1" | - |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.24 Search vendor "Tuxfamily" for product "Chrony" and version "1.24" | - |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.24 Search vendor "Tuxfamily" for product "Chrony" and version "1.24" | pre1 |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.25 Search vendor "Tuxfamily" for product "Chrony" and version "1.25" | - |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.25 Search vendor "Tuxfamily" for product "Chrony" and version "1.25" | pre1 |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.25 Search vendor "Tuxfamily" for product "Chrony" and version "1.25" | pre2 |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.26 Search vendor "Tuxfamily" for product "Chrony" and version "1.26" | - |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.26 Search vendor "Tuxfamily" for product "Chrony" and version "1.26" | pre1 |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.27 Search vendor "Tuxfamily" for product "Chrony" and version "1.27" | - |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.27 Search vendor "Tuxfamily" for product "Chrony" and version "1.27" | pre1 |
Affected
| ||||||
Tuxfamily Search vendor "Tuxfamily" | Chrony Search vendor "Tuxfamily" for product "Chrony" | 1.28 Search vendor "Tuxfamily" for product "Chrony" and version "1.28" | pre1 |
Affected
|