cbcvebase.
CVE-2020-14367
published 2020-08-24

CVE-2020-14367: A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while…

PriorityP426medium6CVSS 3.1
AVLACLPRHUINSUCNIHAH
EPSS
0.48%
38.6th percentile
A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writing, chronyd does not check for an existing symbolic link with the same file name. This flaw allows an attacker with privileged access to create a symlink with the default PID file name pointing to any destination file in the system, resulting in data loss and a denial of service due to the path traversal.

Affected

10 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debianchrony< chrony 3.5.1-1 (bookworm)chrony 3.5.1-1 (bookworm)
fedoraprojectfedora
tuxfamilychrony< 3.5.13.5.1
tuxfamilychrony
tuxfamilychrony>= 0 < 3.5.1-13.5.1-1
tuxfamilychrony>= 0 < 3.5.1-13.5.1-1
tuxfamilychrony>= 0 < 3.5.1-13.5.1-1
tuxfamilychrony>= 0 < 3.5.1-13.5.1-1

CVSS provenance

nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv6.0MEDIUM
vendor_debian6.0LOW
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.