CVE Vulnerabilities

CVE-2016-1567

Published: Jan 26, 2016 | Modified: Apr 12, 2025
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
3.6 LOW
AV:N/AC:H/Au:S/C:N/I:P/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

chrony before 1.31.2 and 2.x before 2.2.1 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a skeleton key.

Affected Software

NameVendorStart VersionEnd Version
ChronyTuxfamily*1.31.1 (including)
ChronyTuxfamily2.0 (including)2.0 (including)
ChronyTuxfamily2.1 (including)2.1 (including)
ChronyTuxfamily2.1.1 (including)2.1.1 (including)
ChronyTuxfamily2.2 (including)2.2 (including)
ChronyUbuntuesm-apps/xenial*
ChronyUbuntuesm-infra-legacy/trusty*
ChronyUbuntuprecise*
ChronyUbuntutrusty*
ChronyUbuntutrusty/esm*
ChronyUbuntuupstream*
ChronyUbuntuvivid*
ChronyUbuntuwily*
ChronyUbuntuxenial*
ChronyUbuntuyakkety*
ChronyUbuntuzesty*

References