PT-2020-5837 · Chrony+5 · Chrony+5
Published
2020-08-19
·
Updated
2024-07-04
·
CVE-2020-14367
CVSS v2.0
6.2
Medium
| Vector | AV:L/AC:L/Au:S/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
chrony versions prior to 3.5.1
Description:
A flaw in chrony allows an attacker with privileged access to create a symlink with the default PID file name, pointing to any destination file in the system. This results in data loss and a denial of service due to path traversal. The issue is related to the creation of the PID file under the /var/run/chrony folder during chronyd startup. The vulnerability can be exploited to overwrite any file in the system, compromising the isolation level in chrony.
Recommendations:
For chrony versions prior to 3.5.1, update to version 3.5.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the /var/run/chrony folder to prevent symlink creation. Additionally, monitor system logs for suspicious activity related to the chronyd process.
Fix
DoS
Link Following
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Red Os
Suse
Ubuntu
Chrony