PT-2020-5837 · Chrony+5 · Chrony+5

Published

2020-08-19

·

Updated

2024-07-04

·

CVE-2020-14367

CVSS v2.0

6.2

Medium

VectorAV:L/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions: chrony versions prior to 3.5.1
Description: A flaw in chrony allows an attacker with privileged access to create a symlink with the default PID file name, pointing to any destination file in the system. This results in data loss and a denial of service due to path traversal. The issue is related to the creation of the PID file under the /var/run/chrony folder during chronyd startup. The vulnerability can be exploited to overwrite any file in the system, compromising the isolation level in chrony.
Recommendations: For chrony versions prior to 3.5.1, update to version 3.5.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the /var/run/chrony folder to prevent symlink creation. Additionally, monitor system logs for suspicious activity related to the chronyd process.

Fix

DoS

Link Following

Path traversal

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2700
ALT-PU-2020-2724
BDU:2021-01809
CVE-2020-14367
MGASA-2020-0341
OPENSUSE-SU-2022:0845-1
OPENSUSE-SU-2022_0845-1
OPENSUSE-SU-2024:10682-1
SUSE-SU-2021:4147-1
SUSE-SU-2021_4147-1
SUSE-SU-2022:0845-1
SUSE-SU-2022:0845-2
SUSE-SU-2022_0845-1
USN-4475-1

Affected Products

Alt Linux
Linuxmint
Red Os
Suse
Ubuntu
Chrony