chrony-3.5.1 released (security)

Miroslav Lichvar <[email protected]> Thu, 20 Aug 2020 09:09:16 +0200
Newsgroups gmane.comp.time.chrony.announce
Message-ID <20200820070916.GA2652556__23686.1414088466$1597907423$gmane$org@localhost>
--AqsLC8rIMeq19msA
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

chrony-3.5.1 is now available. It fixes a security issue in writing of
the pidfile.

The source code can be downloaded here:
https://download.tuxfamily.org/chrony/chrony-3.5.1.tar.gz

SHA256 sum:
1ba82f70db85d414cd7420c39858e3ceca4b9eb8b028cbe869512c3a14a2dca7

Changes since version 3.5:

Security fixes
--------------
* Create new file when writing pidfile (CVE-2020-14367)


CVE-2020-14367: Insecure writing of pidfile
-------------------------------------------

When chronyd is configured to save the pidfile in a directory where the
chrony user has write permissions (e.g. /var/run/chrony - the default
since chrony-3.4), an attacker that compromised the chrony user account
could create a symbolic link at the location of the pidfile to make
chronyd starting with root privileges follow the symlink and write its
process ID to a file for which the chrony user doesn't have write
permissions, causing a denial of service, or data loss.

This issue was reported by Matthias Gerstner of SUSE.

--=20
Miroslav Lichvar

--AqsLC8rIMeq19msA
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iF0EABECAB0WIQSLH0qa2nPUAeMIWgtf8G8puh4BOwUCXz4hlAAKCRBf8G8puh4B
Ow8aAJ9XOTLtwQmhGD/NXsXoZU0pkgXCgwCeMrx3flmHgtL+aMhugA/rtx7pQYw=
=ET8X
-----END PGP SIGNATURE-----

--AqsLC8rIMeq19msA--


-- 
To unsubscribe email chrony-announce-request-kWFZVVI9zxvPqho9SqqRMmD2FQJk+8+b@public.gmane.org with "unsubscribe" in the subject.
For help email chrony-announce-request-kWFZVVI9zxvPqho9SqqRMmD2FQJk+8+b@public.gmane.org with "help" in the subject.
Trouble?  Email [email protected]