Lucene search

K
osvGoogleOSV:DLA-414-1
HistoryFeb 12, 2016 - 12:00 a.m.

chrony - security update

2016-02-1200:00:00
Google
osv.dev
10

EPSS

0.015

Percentile

86.8%

chrony before 1.31.2 and 2.x before 2.2.1 do not verify peer
associations of symmetric keys when authenticating packets, which might
allow remote attackers to conduct impersonation attacks via an arbitrary
trusted key, aka a “skeleton key.”