chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Chrony | Tuxfamily | * | 1.31.1 (excluding) |
Red Hat Enterprise Linux 7 | RedHat | chrony-0:2.1.1-1.el7 | * |
Chrony | Ubuntu | lucid | * |
Chrony | Ubuntu | precise | * |
Chrony | Ubuntu | trusty | * |
Chrony | Ubuntu | upstream | * |
Chrony | Ubuntu | utopic | * |
Chrony | Ubuntu | vivid | * |
Chrony | Ubuntu | wily | * |
Chrony | Ubuntu | yakkety | * |
Chrony | Ubuntu | zesty | * |