Vulnerability Name:

CVE-2020-14367 (CCN-187090)

Assigned:2020-08-21
Published:2020-08-21
Updated:2022-12-06
Summary:
CVSS v3 Severity:6.0 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H)
5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): High
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): High
7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:3.6 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): Partial
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2020-14367

Source: secalert@redhat.com
Type: Issue Tracking, Patch, Vendor Advisory
secalert@redhat.com

Source: CCN
Type: chrony Web site
chrony

Source: XF
Type: UNKNOWN
chrony-cve202014367-priv-esc(187090)

Source: secalert@redhat.com
Type: Mailing List, Third Party Advisory
secalert@redhat.com

Source: CCN
Type: oss-sec Mailing List, Fri, 21 Aug 2020 10:57:25 +0200
chrony: CVE-2020-14367: unsafe pidfile creation allows privilege escalation from chrony user to root

Source: secalert@redhat.com
Type: Third Party Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Third Party Advisory
secalert@redhat.com

Oval Definitions
Definition IDClassTitleLast Modified
oval:org.opensuse.security:def:7461
P
chrony-4.1-150400.19.4 on GA media (Moderate)
2023-06-12
oval:org.opensuse.security:def:52000
P
Security update for less (Moderate)
2023-02-10
oval:org.opensuse.security:def:2887
P
chrony-4.1-150400.19.4 on GA media (Moderate)
2022-06-22
oval:org.opensuse.security:def:94517
P
chrony-4.1-150400.19.4 on GA media (Moderate)
2022-06-22
oval:org.opensuse.security:def:42437
P
Security update for chrony (Moderate)
2022-04-19
oval:org.opensuse.security:def:119151
P
Security update for chrony (Moderate)
2022-03-15
oval:org.opensuse.security:def:973
P
Security update for chrony (Moderate)
2022-03-15
oval:org.opensuse.security:def:99227
P
(Moderate)
2022-03-15
oval:org.opensuse.security:def:100437
P
(Moderate)
2022-03-15
oval:org.opensuse.security:def:99501
P
(Moderate)
2022-03-15
oval:org.opensuse.security:def:100771
P
(Moderate)
2022-03-15
oval:org.opensuse.security:def:42214
P
Security update for chrony (Moderate)
2022-03-15
oval:org.opensuse.security:def:99763
P
(Moderate)
2022-03-15
oval:org.opensuse.security:def:101665
P
Security update for chrony (Moderate)
2022-03-15
oval:org.opensuse.security:def:42357
P
Security update for chrony (Moderate)
2022-03-15
oval:org.opensuse.security:def:100099
P
(Moderate)
2022-03-15
oval:org.opensuse.security:def:112074
P
chrony-4.1-5.2 on GA media (Moderate)
2022-01-17
oval:org.opensuse.security:def:58075
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:51726
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:31336
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:86187
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:60440
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:56109
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:33759
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:29464
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:88554
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:84256
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:58889
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:125645
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:31723
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:86716
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:82671
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:57159
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:34017
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:30166
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:89237
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:84714
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:59582
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:126813
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:55287
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:32252
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:23738
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:87530
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:83373
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:57546
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:5939
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:34617
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:30286
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:89495
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:85800
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:59840
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:127210
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:55989
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:33066
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:24012
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:88237
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:83493
P
Security update for chrony (Moderate)
2021-12-22
oval:org.opensuse.security:def:105617
P
chrony-4.1-5.2 on GA media (Moderate)
2021-10-01
BACK