{"id":"UBUNTU-CVE-2012-4502","details":"Multiple integer overflows in pktlength.c in Chrony before 1.29 allow remote attackers to cause a denial of service (crash) via a crafted (1) REQ_SUBNETS_ACCESSED or (2) REQ_CLIENT_ACCESSES command request to the PKL_CommandLength function or crafted (3) RPY_SUBNETS_ACCESSED, (4) RPY_CLIENT_ACCESSES, (5) RPY_CLIENT_ACCESSES_BY_INDEX, or (6) RPY_MANUAL_LIST command reply to the PKL_ReplyLength function, which triggers an out-of-bounds read or buffer overflow.  NOTE: versions 1.27 and 1.28 do not require authentication to exploit.","modified":"2025-07-16T07:31:01.716434Z","published":"2013-11-05T21:55:00Z","withdrawn":"2025-07-18T16:42:47Z","upstream":["CVE-2012-4502"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2012-4502"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2012-4502"}],"affected":[{"package":{"name":"chrony","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/chrony@1.29-1?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.29-1"}]}],"versions":["1.26-4"],"ecosystem_specific":{"binaries":[{"binary_name":"chrony","binary_version":"1.29-1"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2012/UBUNTU-CVE-2012-4502.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"medium"}]}