Bug 27166 - chrony new security issue CVE-2020-14367
Summary: chrony new security issue CVE-2020-14367
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2020-08-21 19:42 CEST by David Walser
Modified: 2020-08-23 17:29 CEST (History)
3 users (show)

See Also:
Source RPM: chrony-3.4-2.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2020-08-21 19:42:58 CEST
Upstream has issued an advisory today (August 21):
https://www.openwall.com/lists/oss-security/2020/08/21/1

Updated package uploaded for Cauldron.  Patched package uploaded for Mageia 7.

Advisory:
========================

Updated chrony package fixes security vulnerability:

Chrony's method of opening its PID file could allow a compromised chrony user
account to overwrite files in certain parts of the filesystem with chrony's
PID, using a symlink attack (CVE-2020-14367).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14367
https://www.openwall.com/lists/oss-security/2020/08/21/1
========================

Updated packages in core/updates_testing:
========================
chrony-3.4-2.1.mga7

from chrony-3.4-2.1.mga7.src.rpm
David Walser 2020-08-21 19:45:33 CEST

QA Contact: (none) => security
Component: RPM Packages => Security

Comment 1 Thomas Andrews 2020-08-22 03:52:29 CEST
64-bit Plasma system. No installation issues.

Disabled NTP, set the clock to the wrong time enabled NTP again. Time was automatically reset. Looks good.

OKing and validating. Advisory in Comment 0.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update
Whiteboard: (none) => MGA7-64-OK

Aurelien Oudelet 2020-08-22 16:38:57 CEST

Keywords: (none) => advisory
CC: (none) => ouaurelien

Comment 2 Mageia Robot 2020-08-22 21:28:17 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0341.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED

Comment 3 David Walser 2020-08-23 17:29:50 CEST
Fedora has issued an advisory for this today (August 23):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/6WKABKNLCSC3MACCWU6OM2YGWVWFWFMU/

Severity: normal => major


Note You need to log in before you can comment on or make changes to this bug.