All errata/sisyphus/ALT-PU-2017-1975-1
ALT-PU-2017-1975-1

Package update chrony in branch sisyphus

Version3.1-alt1.S1
Published2017-08-04
Max severityHIGH
Severity:

Closed issues (1)

CVE-2016-1567
HIGH8.1

chrony before 1.31.2 and 2.x before 2.2.1 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."

Published: 2016-01-26Modified: 2025-04-12
CVSS 2.0MEDIUM 6.8
CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:P
CVSS 3.xHIGH 8.1
CVSS:3.x/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H