CVE-2015-1821
published 2015-04-16CVE-2015-1821: Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute arbitrary…
PriorityP335medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
3.44%
87.6th percentile
Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute arbitrary code by configuring the (1) NTP or (2) cmdmon access with a subnet size that is indivisible by four and an address with a nonzero bit in the subnet remainder.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | chrony | < chrony 1.30-2 (bookworm) | chrony 1.30-2 (bookworm) |
| debian | debian_linux | — | — |
| tuxfamily | chrony | <= 1.31 | — |
| tuxfamily | chrony | >= 0 < 1.30-2 | 1.30-2 |
| tuxfamily | chrony | >= 0 < 1.30-2 | 1.30-2 |
| tuxfamily | chrony | >= 0 < 1.30-2 | 1.30-2 |
| tuxfamily | chrony | >= 0 < 1.30-2 | 1.30-2 |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chrony: Heap out of bound write in address filter
vendor_redhat·2015-04-07·CVSS 6.5
CVE-2015-1821 [MEDIUM] CWE-122 chrony: Heap out of bound write in address filter
chrony: Heap out of bound write in address filter
Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute arbitrary code by configuring the (1) NTP or (2) cmdmon access with a subnet size that is indivisible by four and an address with a nonzero bit in the subnet remainder.
An out-of-bounds write flaw was found in the way Chrony stored certain addresses when configuring NTP or cmdmon access. An attacker that has the command key and is allowed to access cmdmon (only localhost is allowed by default) could use this flaw to crash chronyd or, possibly, execute arbitrary code with the privileges of the chronyd process.
Debian
CVE-2015-1821: chrony - Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated u...
vendor_debian·2015·CVSS 6.5
CVE-2015-1821 [MEDIUM] CVE-2015-1821: chrony - Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated u...
Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute arbitrary code by configuring the (1) NTP or (2) cmdmon access with a subnet size that is indivisible by four and an address with a nonzero bit in the subnet remainder.
Scope: local
bookworm: resolved (fixed in 1.30-2)
bullseye: resolved (fixed in 1.30-2)
forky: resolved (fixed in 1.30-2)
sid: resolved (fixed in 1.30-2)
trixie: resolved (fixed in 1.30-2)
GHSA
GHSA-cm73-xw9w-xqmm: Heap-based buffer overflow in chrony before 1
ghsa_unreviewed·2022-05-17
CVE-2015-1821 [MEDIUM] CWE-119 GHSA-cm73-xw9w-xqmm: Heap-based buffer overflow in chrony before 1
Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute arbitrary code by configuring the (1) NTP or (2) cmdmon access with a subnet size that is indivisible by four and an address with a nonzero bit in the subnet remainder.
OSV
CVE-2015-1821: Heap-based buffer overflow in chrony before 1
osv·2015-04-16·CVSS 6.5
CVE-2015-1821 [MEDIUM] CVE-2015-1821: Heap-based buffer overflow in chrony before 1
Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute arbitrary code by configuring the (1) NTP or (2) cmdmon access with a subnet size that is indivisible by four and an address with a nonzero bit in the subnet remainder.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1822 CVE-2015-1821 chrony: various flaws [fedora-all]
bugzilla·2015-04-07·CVSS 6.5
CVE-2015-1822 [MEDIUM] CVE-2015-1822 CVE-2015-1821 chrony: various flaws [fedora-all]
CVE-2015-1822 CVE-2015-1821 chrony: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While o
Bugzilla
CVE-2015-1822 CVE-2015-1821 chrony: various flaws [epel-all]
bugzilla·2015-04-07·CVSS 6.5
CVE-2015-1822 [MEDIUM] CVE-2015-1822 CVE-2015-1821 chrony: various flaws [epel-all]
CVE-2015-1822 CVE-2015-1821 chrony: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora EPEL.
Bugzilla
CVE-2015-1821 chrony: Heap out of bound write in address filter
bugzilla·2015-04-07·CVSS 6.5
CVE-2015-1821 [MEDIUM] CVE-2015-1821 chrony: Heap out of bound write in address filter
CVE-2015-1821 chrony: Heap out of bound write in address filter
Miroslav Lichvar of Red Hat reports:
When NTP or cmdmon access is configured (from chrony.conf or over
authenticated cmdmon) with a subnet size that is not divisible by 4
and address that has nonzero bits in the 4-bit subnet remainder (e.g.
f0::/3), the TableNode array index is calculated incorrectly and it
may write past the array.
Discussion:
Acknowledgements:
This issue was discovered by Miroslav Lichvár of Red Hat.
---
Created chrony tracking bugs for this issue:
Affects: epel-all [bug 1209633]
---
Created chrony tracking bugs for this issue:
Affects: fedora-all [bug 1209634]
---
This issue was fixed upstream:
http://chrony.tuxfamily.org/News.html
The updated version is available at:
http://download.tuxfami
http://listengine.tuxfamily.org/chrony.tuxfamily.org/chrony-announce/2015/04/msg00002.htmlhttp://www.debian.org/security/2015/dsa-3222http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/73955https://security.gentoo.org/glsa/201507-01http://listengine.tuxfamily.org/chrony.tuxfamily.org/chrony-announce/2015/04/msg00002.htmlhttp://www.debian.org/security/2015/dsa-3222http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/73955https://security.gentoo.org/glsa/201507-01
2015-04-16
Published