Link following in chrony - CVE-2020-14367
Published: August 31, 2020
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to a symlink following issue when creating the PID file under the "/var/run/chrony" folder. A remote authenticated attacker can create a symlink with the default PID file name pointing to any destination file in the system, resulting in data loss and a denial of service (DoS).
Affected software
Gentoo Linux
Amazon Linux AMI
SUSE Manager Proxy
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Installer
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
Ubuntu
Fedora
libx11 (Alpine package)
augeas-debuginfo
augeas
augeas-debugsource
augeas-lenses
libaugeas0
libaugeas0-debuginfo
augeas-devel
chrony (Ubuntu package)
chrony
chrony-debugsource
chrony-debuginfo
chrony-pool-suse
chrony-pool-empty
How to mitigate CVE-2020-14367
libx11 (Alpine package) - update to 1.6.12-r0
augeas-debuginfo - update to 1.10.1-3.9.1
augeas - update to 1.10.1-3.9.1
augeas-debugsource - update to 1.10.1-3.9.1
augeas-lenses - update to 1.10.1-3.9.1
libaugeas0 - update to 1.10.1-3.9.1
libaugeas0-debuginfo - update to 1.10.1-3.9.1
augeas-devel - update to 1.10.1-3.9.1
chrony (Ubuntu package) - addressed in versions 3.2-4ubuntu4.5, 3.5-6ubuntu6.2
chrony - update to 3.5.1-1.fc32
chrony - addressed in versions 4.1-5.9.1, 4.1-150300.16.3.1
chrony-debugsource - addressed in versions 4.1-5.9.1, 4.1-150300.16.3.1
chrony-debuginfo - addressed in versions 4.1-5.9.1, 4.1-150300.16.3.1
chrony-pool-suse - update to 4.1-150300.16.3.1
chrony-pool-empty - update to 4.1-150300.16.3.1