|
|
Log in / Subscribe / Register

Debian-LTS alert DLA-414-1 (chrony)

From:  Antoine Beaupré <anarcat@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 414-1] chrony security update
Date:  Fri, 12 Feb 2016 18:40:12 -0500
Message-ID:  <20160212234012.GA23634@angela.anarcat.ath.cx>

Package : chrony Version : 1.24-3+squeeze3 CVE ID : CVE-2016-1567 Debian Bug : 812923 chrony before 1.31.2 and 2.x before 2.2.1 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds