PT-2020-5837 · Chrony+5 · Chrony+5

CVE-2020-14367

·

Published

2020-08-19

·

Updated

2024-07-04

CVSS v2.0

6.2

Medium

VectorAV:L/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions: chrony versions prior to 3.5.1
Description: A flaw in chrony allows an attacker with privileged access to create a symlink with the default PID file name, pointing to any destination file in the system. This results in data loss and a denial of service due to path traversal. The issue is related to the creation of the PID file under the /var/run/chrony folder during chronyd startup. The vulnerability can be exploited to overwrite any file in the system, compromising the isolation level in chrony.
Recommendations: For chrony versions prior to 3.5.1, update to version 3.5.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the /var/run/chrony folder to prevent symlink creation. Additionally, monitor system logs for suspicious activity related to the chronyd process.

Fix

DoS

Link Following

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2700
ALT-PU-2020-2724
BDU:2021-01809
CVE-2020-14367
MGASA-2020-0341
OPENSUSE-SU-2022:0845-1
OPENSUSE-SU-2022_0845-1
OPENSUSE-SU-2024:10682-1
SUSE-SU-2021:4147-1
SUSE-SU-2021_4147-1
SUSE-SU-2022:0845-1
SUSE-SU-2022:0845-2
SUSE-SU-2022_0845-1
USN-4475-1

Affected Products

Alt Linux
Linuxmint
Red Os
Suse
Ubuntu
Chrony