CVE-2014-0021: High severity Chrony Project Chrony vulnerability
Published Nov 15, 2019
·Updated
Chrony before 1.29.1 has traffic amplification in cmdmon protocol
Affected Software
7 affected componentsFixes available
Chrony Project Chrony<1.29
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Fedoraproject Fedora=19
Fedoraproject Fedora=20
debian/chrony
4.0-8+deb11u24.3-2+deb12u14.6.1-34.8-2
Event History
Nov 15, 2019
CVE Published
via MITRE·02:35 PM
Data Sourced
via MITRE·02:35 PM
DescriptionWeakness
Feb 18, 2026
Data Sourced
via Debian·06:00 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-0021?
CVE-2014-0021 has a medium severity due to potential traffic amplification attacks that can affect the cmdmon protocol in Chrony.
2
How do I fix CVE-2014-0021?
To fix CVE-2014-0021, upgrade Chrony to versions 1.29.1 or later.
3
What versions of Chrony are affected by CVE-2014-0021?
Chrony versions prior to 1.29.1 are affected by CVE-2014-0021.
4
Which platforms are impacted by CVE-2014-0021?
CVE-2014-0021 impacts Debian and Fedora platforms running affected versions of Chrony.
5
Is CVE-2014-0021 a remote code execution vulnerability?
No, CVE-2014-0021 is not a remote code execution vulnerability but involves traffic amplification risks.