4
CVSSv2

CVE-2015-1853

Published: 09/12/2019 Updated: 13/02/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

chrony prior to 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tuxfamily chrony

Vendor Advisories

Synopsis Moderate: chrony security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic Updated chrony packages that fix three security issues, several bugs, andadd various enhancements are now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this updat ...
Debian Bug report logs - #782160 chrony: Multiple issues: CVE-2015-1821 CVE-2015-1822 CVE-2015-1853 Package: src:chrony; Maintainer for src:chrony is Vincent Blut <vincentdebian@freefr>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 8 Apr 2015 18:09:02 UTC Severity: grave Tags: fixed-upstream, p ...
Miroslav Lichvar of Red Hat discovered multiple vulnerabilities in chrony, an alternative NTP client and server: CVE-2015-1821 Using particular address/subnet pairs when configuring access control would cause an invalid memory write This could allow attackers to cause a denial of service (crash) or execute arbitrary code CVE-2015-182 ...
As reported <a href="chronytuxfamilyorg/Newshtml">upstream</a>: When NTP or cmdmon access was configured (from chronyconf or via authenticated cmdmon) with a subnet size that is indivisible by 4 and an address that has nonzero bits in the 4-bit subnet remainder (eg 192168150/22 or f000::/3), the new setting was written t ...
Impact: Moderate Public Date: 2015-04-07 CWE: CWE-345 Bugzilla: 1209572: CVE-2015-1853 chrony: authenti ...