CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:N/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
Percentile
89.9%
Issue Overview:
It was reported that the cmdmon protocol implemented in chrony was found to be vulnerable to DDoS attacks using traffic amplification. By default, commands are allowed only from localhost, but it’s possible to configure chronyd to allow commands from any address. This could allow a remote attacker to cause a DoS, which could cause excessive resource usage.
Affected Packages:
chrony
Issue Correction:
Run yum update chrony to update your system.
New Packages:
i686:
chrony-1.29.1-1.8.amzn1.i686
chrony-debuginfo-1.29.1-1.8.amzn1.i686
src:
chrony-1.29.1-1.8.amzn1.src
x86_64:
chrony-debuginfo-1.29.1-1.8.amzn1.x86_64
chrony-1.29.1-1.8.amzn1.x86_64
Red Hat: CVE-2014-0021
Mitre: CVE-2014-0021
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Amazon Linux | 1 | i686 | chrony | < 1.29.1-1.8.amzn1 | chrony-1.29.1-1.8.amzn1.i686.rpm |
Amazon Linux | 1 | i686 | chrony-debuginfo | < 1.29.1-1.8.amzn1 | chrony-debuginfo-1.29.1-1.8.amzn1.i686.rpm |
Amazon Linux | 1 | x86_64 | chrony-debuginfo | < 1.29.1-1.8.amzn1 | chrony-debuginfo-1.29.1-1.8.amzn1.x86_64.rpm |
Amazon Linux | 1 | x86_64 | chrony | < 1.29.1-1.8.amzn1 | chrony-1.29.1-1.8.amzn1.x86_64.rpm |
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:N/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
Percentile
89.9%