CVE-2015-1821
chrony - security update
EPSS 3.4%
描述
Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute arbitrary code by configuring the (1) NTP or (2) cmdmon access with a subnet size that is indivisible by four and an address with a nonzero bit in the subnet remainder.
如何修補 CVE-2015-1821
要修補 CVE-2015-1821,請將受影響套件升級到下列已修補版本。
- Debian/chrony—升級至 1.30-2 或更新版本
- Debian/chrony—升級至 1.24-3+squeeze2 或更新版本
- Debian/chrony—升級至 1.24-3.1+deb7u3 或更新版本
CVE-2015-1821 正在被利用嗎?
低 — EPSS 為 3.4%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 1.30-2
- from 0, < 1.24-3+squeeze2
- from 0, < 1.24-3.1+deb7u3