CVE-2016-1567
Severity CVSS v4.0:
Pending analysis
Type:
CWE-254
Security Features
Publication date:
26/01/2016
Last modified:
12/04/2025
Description
chrony before 1.31.2 and 2.x before 2.2.1 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:tuxfamily:chrony:*:*:*:*:*:*:*:* | 1.31.1 (including) | |
| cpe:2.3:a:tuxfamily:chrony:2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:tuxfamily:chrony:2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:tuxfamily:chrony:2.1.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:tuxfamily:chrony:2.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://chrony.tuxfamily.org/news.html#_20_jan_2016_chrony_2_2_1_and_chrony_1_31_2_released
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176559.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175969.html
- http://www.talosintel.com/reports/TALOS-2016-0071/
- http://chrony.tuxfamily.org/news.html#_20_jan_2016_chrony_2_2_1_and_chrony_1_31_2_released
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176559.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175969.html
- http://www.talosintel.com/reports/TALOS-2016-0071/



