CVE-2020-14367
published 2020-08-24CVE-2020-14367: A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while…
PriorityP426medium6CVSS 3.1
AVLACLPRHUINSUCNIHAH
EPSS
0.48%
38.6th percentile
A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writing, chronyd does not check for an existing symbolic link with the same file name. This flaw allows an attacker with privileged access to create a symlink with the default PID file name pointing to any destination file in the system, resulting in data loss and a denial of service due to the path traversal.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | chrony | < chrony 3.5.1-1 (bookworm) | chrony 3.5.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| tuxfamily | chrony | < 3.5.1 | 3.5.1 |
| tuxfamily | chrony | — | — |
| tuxfamily | chrony | >= 0 < 3.5.1-1 | 3.5.1-1 |
| tuxfamily | chrony | >= 0 < 3.5.1-1 | 3.5.1-1 |
| tuxfamily | chrony | >= 0 < 3.5.1-1 | 3.5.1-1 |
| tuxfamily | chrony | >= 0 < 3.5.1-1 | 3.5.1-1 |
CVSS provenance
nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv6.0MEDIUM
vendor_debian6.0LOW
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Chrony vulnerability
vendor_ubuntu·2020-08-27
CVE-2020-14367 Chrony vulnerability
Title: Chrony vulnerability
Summary: Chrony could be made to crash or expose sensitive information.
It was discovered that Chrony incorrectly handled certain symbolic links.
An attacker could possibly use this issue to cause a denial of service or
expose sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
chrony: Insecure writing to PID file
vendor_redhat·2020-08-19·CVSS 6.0
CVE-2020-14367 [MEDIUM] CWE-59 chrony: Insecure writing to PID file
chrony: Insecure writing to PID file
A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writing, chronyd does not check for an existing symbolic link with the same file name. This flaw allows an attacker with privileged access to create a symlink with the default PID file name pointing to any destination file in the system, resulting in data loss and a denial of service due to the path traversal.
A flaw was found in chrony when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writing, chronyd does not check for an
Debian
CVE-2020-14367: chrony - A flaw was found in chrony versions before 3.5.1 when creating the PID file unde...
vendor_debian·2020·CVSS 6.0
CVE-2020-14367 [MEDIUM] CVE-2020-14367: chrony - A flaw was found in chrony versions before 3.5.1 when creating the PID file unde...
A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writing, chronyd does not check for an existing symbolic link with the same file name. This flaw allows an attacker with privileged access to create a symlink with the default PID file name pointing to any destination file in the system, resulting in data loss and a denial of service due to the path traversal.
Scope: local
bookworm: resolved (fixed in 3.5.1-1)
bullseye: resolved (fixed in 3.5.1-1)
forky: resolved (fixed in 3.5.1-1)
sid: resolved (fixed in 3.5.1-1)
trixie: resolved (fixed in 3.5.1-1)
GHSA
GHSA-73h7-c2xm-9mrv: A flaw was found in chrony versions before 3
ghsa_unreviewed·2022-05-24
CVE-2020-14367 [LOW] CWE-59 GHSA-73h7-c2xm-9mrv: A flaw was found in chrony versions before 3
A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writing, chronyd does not check for an existing symbolic link with the same file name. This flaw allows an attacker with privileged access to create a symlink with the default PID file name pointing to any destination file in the system, resulting in data loss and a denial of service due to the path traversal.
OSV
CVE-2020-14367: A flaw was found in chrony versions before 3
osv·2020-08-24·CVSS 6.0
CVE-2020-14367 [MEDIUM] CVE-2020-14367: A flaw was found in chrony versions before 3
A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writing, chronyd does not check for an existing symbolic link with the same file name. This flaw allows an attacker with privileged access to create a symlink with the default PID file name pointing to any destination file in the system, resulting in data loss and a denial of service due to the path traversal.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14367 chrony: Insecure writing to PID file [fedora-all]
bugzilla·2020-08-19·CVSS 6.0
CVE-2020-14367 [MEDIUM] CVE-2020-14367 chrony: Insecure writing to PID file [fedora-all]
CVE-2020-14367 chrony: Insecure writing to PID file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. W
Bugzilla
CVE-2020-14367 chrony: Insecure writing to PID file
bugzilla·2020-08-19·CVSS 6.0
CVE-2020-14367 [MEDIUM] CVE-2020-14367 chrony: Insecure writing to PID file
CVE-2020-14367 chrony: Insecure writing to PID file
When chronyd is configured to save the pidfile in a directory where the chrony user has write permissions (e.g. /var/run/chrony - the default since chrony-3.4), an attacker that compromised the chrony user account could create a symbolic link at the location of the pidfile to make chronyd starting with root privileges follow the symlink and write its process ID to a file for which the chrony user doesn't have write permissions, causing a denial of service, or data loss.
Discussion:
Created chrony tracking bugs for this issue:
Affects: fedora-all [bug 1870299]
---
Acknowledgments:
Name: Matthias Gerstner (Suse)
---
There's an issue on chrony when creating the PID file under /var/run/chrony folder. The file is created during chrony
https://bugzilla.redhat.com/show_bug.cgi?id=1870298https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WKABKNLCSC3MACCWU6OM2YGWVWFWFMU/https://security.gentoo.org/glsa/202008-23https://usn.ubuntu.com/4475-1/https://bugzilla.redhat.com/show_bug.cgi?id=1870298https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WKABKNLCSC3MACCWU6OM2YGWVWFWFMU/https://security.gentoo.org/glsa/202008-23https://usn.ubuntu.com/4475-1/
2020-08-24
Published