Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian: DSA-3222-1 Critical: Chrony DoS and Code Execution Risks

debian
Calendar Grey April 12, 2015
Debian Logo
Several flaws were identified in the chrony software, putting systems at risk of service disruption and potential code execution.
Miroslav Lichvar of Red Hat discovered multiple vulnerabilities in chrony, an alternative NTP client and server: CVE-2015-1821

Summary

CVE-2015-1821

Using particular address/subnet pairs when configuring access control
would cause an invalid memory write. This could allow attackers to
cause a denial of service (crash) or execute arbitrary code.

CVE-2015-1822

When allocating memory to save unacknowledged replies to authenticated
command requests, a pointer would be left uninitialized, which could
trigger an invalid memory write. This could allow attackers to cause a
denial of service (crash) or execute arbitrary code.

CVE-2015-1853

When peering with other NTP hosts using authenticated symmetric
association, the internal state variables would be updated before the
MAC of the NTP messages was validated. This could allow a remote
attacker to cause a denial of service by impeding synchronization
between NTP peers.

For the stable distribution (wheezy), these problems have been fixed in
version 1.24-3.1+deb7u3.

For the unstable distribution (sid), these problems have been fixed in
version 1.3...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: chrony
CVE ID: CVE-2015-1821 CVE-2015-1822 CVE-2015-1853

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here