CVE Vulnerabilities

CVE-2016-1567

Published: Jan 26, 2016 | Modified: Dec 06, 2016
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
3.6 LOW
AV:N/AC:H/Au:S/C:N/I:P/A:P
RedHat/V3
Ubuntu
LOW

chrony before 1.31.2 and 2.x before 2.2.1 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a skeleton key.

Affected Software

Name Vendor Start Version End Version
Chrony Tuxfamily * 1.31.1 (including)
Chrony Tuxfamily 2.0 (including) 2.0 (including)
Chrony Tuxfamily 2.1 (including) 2.1 (including)
Chrony Tuxfamily 2.1.1 (including) 2.1.1 (including)
Chrony Tuxfamily 2.2 (including) 2.2 (including)
Chrony Ubuntu precise *
Chrony Ubuntu trusty *
Chrony Ubuntu upstream *
Chrony Ubuntu vivid *
Chrony Ubuntu wily *
Chrony Ubuntu xenial *
Chrony Ubuntu yakkety *
Chrony Ubuntu zesty *

References