chrony: distributed denial of service via amplification
Package(s): | chrony |
CVE #(s): | CVE-2014-0021
|
Created: | February 6, 2014 |
Updated: | February 20, 2014 |
Description: |
From the Red Hat bugzilla entry:
Miroslav Lichvar from Red Hat reports that the cmdmon protocol implemented in chrony was found to be vulnerable to DDoS attacks using traffic amplification. By default, commands are allowed only from localhost, but it's possible to configure chronyd to allow commands from any address. This could allow a remote attacker to cause a DoS, which could cause excessive resource usage. |
Alerts: |
|