CVE-2015-1853
published 2019-12-09CVE-2015-1853: chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP…
PriorityP431medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.70%
74.6th percentile
chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrony | chrony | — | — |
| debian | chrony | < chrony 1.30-2 (bookworm) | chrony 1.30-2 (bookworm) |
| tuxfamily | chrony | < 1.31.1 | 1.31.1 |
| tuxfamily | chrony | >= 0 < 1.30-2 | 1.30-2 |
| tuxfamily | chrony | >= 0 < 1.30-2 | 1.30-2 |
| tuxfamily | chrony | >= 0 < 1.30-2 | 1.30-2 |
| tuxfamily | chrony | >= 0 < 1.30-2 | 1.30-2 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chrony: authentication doesn't protect symmetric associations against DoS attacks
vendor_redhat·2015-04-07·CVSS 6.5
CVE-2015-1853 [MEDIUM] CWE-345 chrony: authentication doesn't protect symmetric associations against DoS attacks
chrony: authentication doesn't protect symmetric associations against DoS attacks
chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.
A denial of service flaw was found in the way chrony hosts that were peering with each other authenticated themselves before updating their internal state variables. An attacker could send packets to one peer host, which could cascade to other peers, and stop the synchronization process among the reached peers.
Debian
CVE-2015-1853: chrony - chrony before 1.31.1 does not properly protect state variables in authenticated ...
vendor_debian·2015·CVSS 6.5
CVE-2015-1853 [MEDIUM] CVE-2015-1853: chrony - chrony before 1.31.1 does not properly protect state variables in authenticated ...
chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.
Scope: local
bookworm: resolved (fixed in 1.30-2)
bullseye: resolved (fixed in 1.30-2)
forky: resolved (fixed in 1.30-2)
sid: resolved (fixed in 1.30-2)
trixie: resolved (fixed in 1.30-2)
GHSA
GHSA-gf8j-j7q8-vhh5: chrony before 1
ghsa_unreviewed·2022-05-24
CVE-2015-1853 [MEDIUM] GHSA-gf8j-j7q8-vhh5: chrony before 1
chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.
OSV
CVE-2015-1853: chrony before 1
osv·2019-12-09·CVSS 6.5
CVE-2015-1853 [MEDIUM] CVE-2015-1853: chrony before 1
chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1853 chrony: authentication doesn't protect symmetric associations against DoS attacks [fedora-all]
bugzilla·2015-04-07·CVSS 6.5
CVE-2015-1853 [MEDIUM] CVE-2015-1853 chrony: authentication doesn't protect symmetric associations against DoS attacks [fedora-all]
CVE-2015-1853 chrony: authentication doesn't protect symmetric associations against DoS attacks [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2015-1853 chrony: authentication doesn't protect symmetric associations against DoS attacks
bugzilla·2015-04-07·CVSS 6.5
CVE-2015-1853 [MEDIUM] CVE-2015-1853 chrony: authentication doesn't protect symmetric associations against DoS attacks
CVE-2015-1853 chrony: authentication doesn't protect symmetric associations against DoS attacks
Miroslav Lichvar of Red Hat reports:
An attacker knowing that NTP hosts A and B are peering with each other (symmetric association) can send a packet to host A with source address of B which will set the NTP state variables on A to the values sent by the attacker. Host A will then send on its next poll to B a packet with originate timestamp that doesn't match the transmit timestamp of B and the packet will be dropped. If the attacker does this periodically for both hosts, they won't be able to synchronize to each other. This is a known denial-of-service attack, described at [1].
According to the document the NTP authentication is supposed to protect symmetric associations against this attack,
Bugzilla
CVE-2015-1853 chrony: authentication doesn't protect symmetric associations against DoS attacks [epel-all]
bugzilla·2015-04-07·CVSS 6.5
CVE-2015-1853 [MEDIUM] CVE-2015-1853 chrony: authentication doesn't protect symmetric associations against DoS attacks [epel-all]
CVE-2015-1853 chrony: authentication doesn't protect symmetric associations against DoS attacks [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2015-1799 ntp: authentication doesn't protect symmetric associations against DoS attacks
bugzilla·2015-03-06·CVSS 4.3
CVE-2015-1799 [MEDIUM] CVE-2015-1799 ntp: authentication doesn't protect symmetric associations against DoS attacks
CVE-2015-1799 ntp: authentication doesn't protect symmetric associations against DoS attacks
An attacker knowing that NTP hosts A and B are peering with each other (symmetric association) can send a packet to host A with source address of B which will set the NTP state variables on A to the values sent by the attacker. Host A will then send on its next poll to B a packet with originate timestamp that doesn't match the transmit timestamp of B and the packet will be dropped. If the attacker does this periodically for both hosts, they won't be able to synchronize to each other. This is a known denial-of-service attack, described at [1].
According to the document the NTP authentication is supposed to protect symmetric associations against this attack, but that doesn't seem to be the case. Th
2019-12-09
Published