CVE-2012-4503
EPSS 3.1%
描述
cmdmon.c in Chrony before 1.29 allows remote attackers to obtain potentially sensitive information from stack memory via vectors related to (1) an invalid subnet in a RPY_SUBNETS_ACCESSED command to the handle_subnets_accessed function or (2) a RPY_CLIENT_ACCESSES command to the handle_client_accesses function when client logging is disabled, which causes uninitialized data to be included in a reply.
如何修補 CVE-2012-4503
要修補 CVE-2012-4503,請將受影響套件升級到下列已修補版本。
- Debian/chrony—升級至 1.29-1 或更新版本
CVE-2012-4503 正在被利用嗎?
低 — EPSS 為 3.1%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 1.29-1