{"id":"MGASA-2016-0038","summary":"Updated chrony packages fix security vulnerability","details":"In chrony before 1.31.2, when used with symmetric key encryption, the\nclient would accept packets encrypted with keys for any configured server,\nallowing a server to impersonate other servers to clients, thus performing\na man-in-the-middle attack (CVE-2016-1567).\n","modified":"2026-04-16T06:25:06.680010832Z","published":"2016-01-29T11:02:50Z","upstream":["CVE-2016-1567"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2016-0038.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=17605"},{"type":"WEB","url":"http://chrony.tuxfamily.org/news.html#_20_jan_2016_chrony_2_2_1_and_chrony_1_31_2_released"},{"type":"WEB","url":"http://www.talosintel.com/reports/TALOS-2016-0071/"}],"affected":[{"package":{"name":"chrony","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/chrony?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.31.2-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0038.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}