CVE-2012-4503Sensitive Information Exposure in Chrony

Severity
5.0MEDIUMNVD
EPSS
0.4%
top 39.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 5
Latest updateMay 17

Description

cmdmon.c in Chrony before 1.29 allows remote attackers to obtain potentially sensitive information from stack memory via vectors related to (1) an invalid subnet in a RPY_SUBNETS_ACCESSED command to the handle_subnets_accessed function or (2) a RPY_CLIENT_ACCESSES command to the handle_client_accesses function when client logging is disabled, which causes uninitialized data to be included in a reply.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debiantuxfamily/chrony< 1.29-1+3
NVDtuxfamily/chrony1.28+16

Patches

🔴Vulnerability Details

3
GHSA
GHSA-53c9-c34f-h6w7: cmdmon2022-05-17
OSV
CVE-2012-4503: cmdmon2013-11-05
CVEList
CVE-2012-4503: cmdmon2013-11-05

📋Vendor Advisories

2
Red Hat
chrony: Two security flaws fixed in chrony-1.29 release2013-08-09
Debian
CVE-2012-4503: chrony - cmdmon.c in Chrony before 1.29 allows remote attackers to obtain potentially sen...2012

💬Community

3
Bugzilla
CVE-2012-4503 CVE-2012-4502 chrony: Two security flaws fixed in chrony-1.29 release [epel-all]2013-08-09
Bugzilla
CVE-2012-4503 CVE-2012-4502 chrony: Two security flaws fixed in chrony-1.29 release [fedora-all]2013-08-09
Bugzilla
CVE-2012-4502 CVE-2012-4503 chrony: Two security flaws fixed in chrony-1.29 release2012-08-07
CVE-2012-4503 — Sensitive Information Exposure | cvebase