MGASA-2014-0052
Dashboard / Vulnerabilities / MGASA-2014-0052
Summary: Updated chrony package fixes security vulnerability
Details: Updated chrony package fixes security vulnerability: In the chrony control protocol some replies are significantly larger than their requests, which allows an attacker to use it in an amplification attack (CVE-2014-0021). Note: in the default configuration, cmdallow is restricted to localhost, so significant amplification is only possible if the configuration has been changed to allow cmdallow from other hosts. Even from hosts whose access is denied, minor amplification is still possible.
References: https://advisories.mageia.org/MGASA-2014-0052.html, https://bugs.mageia.org/show_bug.cgi?id=12347, http://chrony.tuxfamily.org/News.html
Affected packages
Package
Name: chrony
Purl: pkg:rpm/mageia/chrony?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
