{"id":"MGASA-2014-0052","summary":"Updated chrony package fixes security vulnerability","details":"Updated chrony package fixes security vulnerability:\n\nIn the chrony control protocol some replies are significantly larger than\ntheir requests, which allows an attacker to use it in an amplification\nattack (CVE-2014-0021).\n\nNote: in the default configuration, cmdallow is restricted to localhost,\nso significant amplification is only possible if the configuration has\nbeen changed to allow cmdallow from other hosts. Even from hosts whose\naccess is denied, minor amplification is still possible.\n","modified":"2026-04-16T06:24:17.507429712Z","published":"2014-02-11T22:13:17Z","upstream":["CVE-2014-0021"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0052.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=12347"},{"type":"WEB","url":"http://chrony.tuxfamily.org/News.html"}],"affected":[{"package":{"name":"chrony","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/chrony?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.29.1-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0052.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}