CVE-2015-1853
chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in…
Does this matter?
Lower severity and a low EPSS score (1.70%). Track it; it rarely justifies an emergency change on its own.
Description
chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.70% probability · 76th percentile
- CISA KEV
- Not listed
- Affected
- tuxfamily/chrony
- Source
- secalert@redhat.com
References
- http://chrony.tuxfamily.org/News.htmlRelease Notes, Vendor Advisory
- https://security.gentoo.org/glsa/201507-01Third Party Advisory
- http://chrony.tuxfamily.org/News.htmlRelease Notes, Vendor Advisory
- https://security.gentoo.org/glsa/201507-01Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.