Candidate: CVE-2014-0021 PublicDate: 2019-11-15 15:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0021 http://listengine.tuxfamily.org/chrony.tuxfamily.org/chrony-dev/2014/01/msg00005.html Description: Chrony before 1.29.1 has traffic amplification in cmdmon protocol Ubuntu-Description: Miroslav Lichvar discovered that Chrony is affected by traffic amplification attacks. A remote attacker could possibly use this issue to obtain sensitive information. Notes: seth-arnold> A fix will likely require protocol changes Bugs: Priority: low Discovered-by: Miroslav Lichvar Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_chrony: upstream_chrony: released (1.19.1,1.29.1) lucid_chrony: ignored (reached end-of-life) precise_chrony: ignored (reached end-of-life) precise/esm_chrony: DNE (precise was deferred [2014-01-22]) quantal_chrony: ignored (reached end-of-life) raring_chrony: ignored (reached end-of-life) saucy_chrony: ignored (reached end-of-life) trusty_chrony: ignored (out of standard support) trusty/esm_chrony: needed utopic_chrony: ignored (reached end-of-life) vivid_chrony: ignored (reached end-of-life) vivid/stable-phone-overlay_chrony: DNE vivid/ubuntu-core_chrony: DNE wily_chrony: ignored (reached end-of-life) xenial_chrony: not-affected (2.1.1-1) yakkety_chrony: ignored (reached end-of-life) zesty_chrony: ignored (reached end-of-life) artful_chrony: not-affected (3.1-5) bionic_chrony: not-affected (3.2-4ubuntu1) cosmic_chrony: not-affected (3.2-4ubuntu1) disco_chrony: not-affected (3.2-4ubuntu1) eoan_chrony: not-affected (3.2-4ubuntu1) focal_chrony: not-affected (3.2-4ubuntu1) groovy_chrony: not-affected (3.2-4ubuntu1) hirsute_chrony: not-affected (3.2-4ubuntu1) impish_chrony: not-affected (3.2-4ubuntu1) jammy_chrony: not-affected (3.2-4ubuntu1) devel_chrony: not-affected (3.2-4ubuntu1)