Home/Product/tuxfamily chrony
Product

tuxfamily chrony

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2020-14367
< 3.5.1
A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created
6.0MEDIUM
CVE-2015-1853
< 1.31.1
chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote at
6.5MEDIUM
CVE-2014-0021
< 1.29
Chrony before 1.29.1 has traffic amplification in cmdmon protocol
7.5HIGH
CVE-2016-1567
<= 1.31.1
chrony before 1.31.2 and 2.x before 2.2.1 do not verify peer associations of symmetric keys when authenticating packets, which mig
8.1HIGH
CVE-2015-1822
<= 1.31
chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which all
CVE-2015-1821
<= 1.31
Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash)
CVE-2012-4503
<= 1.28
cmdmon.c in Chrony before 1.29 allows remote attackers to obtain potentially sensitive information from stack memory via vectors r
CVE-2012-4502
<= 1.28
Multiple integer overflows in pktlength.c in Chrony before 1.29 allow remote attackers to cause a denial of service (crash) via a
CVE-2010-0294
<= 1.23-pre1
chronyd in Chrony before 1.23.1, and possibly 1.24-pre1, generates a syslog message for each unauthorized cmdmon packet, which all
CVE-2010-0293
<= 1.23-pre1
The client logging functionality in chronyd in Chrony before 1.23.1 does not restrict the amount of memory used for storage of cli
CVE-2010-0292
<= 1.23-pre1
The read_from_cmd_socket function in cmdmon.c in chronyd in Chrony before 1.23.1, and 1.24-pre1, allows remote attackers to cause
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin