CVE Vulnerabilities

CVE-2016-1567

Published: Jan 26, 2016 | Modified: Dec 06, 2016
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

chrony before 1.31.2 and 2.x before 2.2.1 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a skeleton key.

Affected Software

Name Vendor Start Version End Version
Chrony Tuxfamily * 1.31.1 (including)
Chrony Tuxfamily 2.0 (including) 2.0 (including)
Chrony Tuxfamily 2.1 (including) 2.1 (including)
Chrony Tuxfamily 2.1.1 (including) 2.1.1 (including)
Chrony Tuxfamily 2.2 (including) 2.2 (including)

References