CVE-2015-1821
Publication date 16 April 2015
Last updated 24 July 2024
Ubuntu priority
Description
Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute arbitrary code by configuring the (1) NTP or (2) cmdmon access with a subnet size that is indivisible by four and an address with a nonzero bit in the subnet remainder.
From the Ubuntu Security Team
Miroslav Lichvár discovered a head-based buffer overflow in chrony. A remote attacker could use this vulnerability to cause a denial of service (crash) or execute arbitrary code.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| chrony | ||
| 18.04 LTS bionic |
Not affected
|
|
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Fixed 1.29-1ubuntu0.1
|
|