2017-08-05
ALT-BU-2017-3275-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Published: 2016-01-26
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2016-1567
chrony before 1.31.2 and 2.x before 2.2.1 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."
Severity: HIGH (8.1)
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
- http://chrony.tuxfamily.org/news.html#_20_jan_2016_chrony_2_2_1_and_chrony_1_31_2_released
- http://chrony.tuxfamily.org/news.html#_20_jan_2016_chrony_2_2_1_and_chrony_1_31_2_released
- FEDORA-2016-6f783d1768
- FEDORA-2016-6f783d1768
- FEDORA-2016-6a0b0ab775
- FEDORA-2016-6a0b0ab775
- http://www.talosintel.com/reports/TALOS-2016-0071/
- http://www.talosintel.com/reports/TALOS-2016-0071/
Package update-kernel updated to version 0.9.10-alt1 for branch sisyphus in task 186621.
Closed bugs
update-kernel обломался обновить модули для ядра