Chrony 1.23 and Prior Multiple Remote Denial of Service Vulnerabilities
BID:38106
Info
Chrony 1.23 and Prior Multiple Remote Denial of Service Vulnerabilities
| Bugtraq ID: | 38106 |
| Class: | Design Error |
| CVE: |
CVE-2010-0292 CVE-2010-0293 CVE-2010-0294 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 04 2010 12:00AM |
| Updated: | Apr 16 2015 06:07PM |
| Credit: | The vendor |
| Vulnerable: |
Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 armel Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Chrony Chrony 1.23 |
| Not Vulnerable: |
Chrony Chrony 1.23.1 Chrony Chrony 1.24 |
Discussion
Chrony 1.23 and Prior Multiple Remote Denial of Service Vulnerabilities
Chrony is prone to multiple remote denial-of-service vulnerabilities because it fails to properly handle certain incoming network packets.
An attacker can exploit these issues to cause the application to consume excessive CPU and network resources and to fill disk space with log messages.
Versions prior to Chrony 1.23.1 and 1.24 are vulnerable.
Chrony is prone to multiple remote denial-of-service vulnerabilities because it fails to properly handle certain incoming network packets.
An attacker can exploit these issues to cause the application to consume excessive CPU and network resources and to fill disk space with log messages.
Versions prior to Chrony 1.23.1 and 1.24 are vulnerable.
Exploit / POC
Chrony 1.23 and Prior Multiple Remote Denial of Service Vulnerabilities
To exploit these issues, attackers can use readily available network tools.
To exploit these issues, attackers can use readily available network tools.
Solution / Fix
Chrony 1.23 and Prior Multiple Remote Denial of Service Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Debian Linux 4.0 amd64
Debian Linux 4.0 ia-32
Debian Linux 4.0 arm
Debian Linux 5.0 hppa
Debian Linux 5.0 ia-64
Debian Linux 4.0 hppa
Debian Linux 4.0 sparc
Debian Linux 4.0 s/390
Debian Linux 5.0 arm
Debian Linux 4.0 powerpc
Debian Linux 4.0 alpha
Debian Linux 5.0 armel
Debian Linux 4.0 mipsel
Debian Linux 5.0 amd64
Debian Linux 5.0 alpha
Debian Linux 5.0 ia-32
Debian Linux 5.0 mips
Debian Linux 5.0 s/390
Debian Linux 5.0 mipsel
Debian Linux 5.0 powerpc
Debian Linux 4.0 ia-64
Chrony Chrony 1.23
Debian Linux 5.0 sparc
Solution:
Updates are available. Please see the references for details.
Debian Linux 4.0 amd64
-
Debian chrony_1.21z-5+etch1_amd64.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.21z-5+e tch1_amd64.deb
Debian Linux 4.0 ia-32
-
Debian chrony_1.21z-5+etch1_i386.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.21z-5+e tch1_i386.deb
Debian Linux 4.0 arm
-
Debian chrony_1.21z-5+etch1_arm.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.21z-5+e tch1_arm.deb
Debian Linux 5.0 hppa
-
Debian chrony_1.23-6+lenny1_hppa.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.23-6+le nny1_hppa.deb
Debian Linux 5.0 ia-64
-
Debian chrony_1.23-6+lenny1_ia64.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.23-6+le nny1_ia64.deb
Debian Linux 4.0 hppa
-
Debian chrony_1.21z-5+etch1_hppa.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.21z-5+e tch1_hppa.deb
Debian Linux 4.0 sparc
-
Debian chrony_1.21z-5+etch1_sparc.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.21z-5+e tch1_sparc.deb
Debian Linux 4.0 s/390
-
Debian chrony_1.21z-5+etch1_s390.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.21z-5+e tch1_s390.deb
Debian Linux 5.0 arm
-
Debian chrony_1.23-6+lenny1_arm.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.23-6+le nny1_arm.deb
Debian Linux 4.0 powerpc
-
Debian chrony_1.21z-5+etch1_powerpc.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.21z-5+e tch1_powerpc.deb
Debian Linux 4.0 alpha
-
Debian chrony_1.21z-5+etch1_alpha.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.21z-5+e tch1_alpha.deb
Debian Linux 5.0 armel
-
Debian chrony_1.23-6+lenny1_armel.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.23-6+le nny1_armel.deb
Debian Linux 4.0 mipsel
-
Debian chrony_1.21z-5+etch1_mipsel.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.21z-5+e tch1_mipsel.deb
Debian Linux 5.0 amd64
-
Debian chrony_1.23-6+lenny1_amd64.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.23-6+le nny1_amd64.deb
Debian Linux 5.0 alpha
-
Debian chrony_1.23-6+lenny1_alpha.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.23-6+le nny1_alpha.deb
Debian Linux 5.0 ia-32
-
Debian chrony_1.23-6+lenny1_i386.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.23-6+le nny1_i386.deb
Debian Linux 5.0 mips
-
Debian chrony_1.23-6+lenny1_mips.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.23-6+le nny1_mips.deb
Debian Linux 5.0 s/390
-
Debian chrony_1.23-6+lenny1_s390.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.23-6+le nny1_s390.deb
Debian Linux 5.0 mipsel
-
Debian chrony_1.23-6+lenny1_mipsel.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.23-6+le nny1_mipsel.deb
Debian Linux 5.0 powerpc
-
Debian chrony_1.23-6+lenny1_powerpc.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.23-6+le nny1_powerpc.deb
Debian Linux 4.0 ia-64
-
Debian chrony_1.21z-5+etch1_ia64.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.21z-5+e tch1_ia64.deb
Chrony Chrony 1.23
-
Chrony chrony-1.23.1.tar.gz
http://download.tuxfamily.org/chrony/chrony-1.23.1.tar.gz -
Chrony chrony-1.24.tar.gz
http://download.tuxfamily.org/chrony/chrony-1.24.tar.gz
Debian Linux 5.0 sparc
-
Debian chrony_1.23-6+lenny1_sparc.deb
http://security.debian.org/pool/updates/main/c/chrony/chrony_1.23-6+le nny1_sparc.deb
References
Chrony 1.23 and Prior Multiple Remote Denial of Service Vulnerabilities
References:
References:
- 4 February 2010: Security Advisory (Chrony)
- Add option to limit clientlog memory (Miroslav Lichvar)
- Chrony Homepage (Chrony)
- Don't reply to invalid chronyc packets (Miroslav Lichvar)
- Limit rate of syslog messages (Miroslav Lichvar)