Advisories ยป MGASA-2016-0038

Updated chrony packages fix security vulnerability

Publication date: 29 Jan 2016
Modification date: 29 Jan 2016
Type: security
Affected Mageia releases : 5
CVE: CVE-2016-1567

Description

In chrony before 1.31.2, when used with symmetric key encryption, the
client would accept packets encrypted with keys for any configured server,
allowing a server to impersonate other servers to clients, thus performing
a man-in-the-middle attack (CVE-2016-1567).
                

References

SRPMS

5/core