[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2015:2058-1 -- SLES ntp

ID: oval:org.secpod.oval:def:89045466Date: (C)2021-08-04   (M)2024-01-29
Class: PATCHFamily: unix




This ntp update provides the following security and non security fixes: - Update to 4.2.8p4 to fix several security issues : * CVE-2015-7871: NAK to the Future: Symmetric association authentication bypass via crypto-NAK * CVE-2015-7855: decodenetnum will ASSERT botch instead of returning FAIL on some bogus values * CVE-2015-7854: Password Length Memory Corruption Vulnerability * CVE-2015-7853: Invalid length data provided by a custom refclock driver could cause a buffer overflow * CVE-2015-7852 ntpq atoascii Memory Corruption Vulnerability * CVE-2015-7851 saveconfig Directory Traversal Vulnerability * CVE-2015-7850 remote config logfile-keyfile * CVE-2015-7849 trusted key use-after-free * CVE-2015-7848 mode 7 loop counter underrun * CVE-2015-7701 Slow memory leak in CRYPTO_ASSOC * CVE-2015-7703 configuration directives pidfile and driftfile should only be allowed locally * CVE-2015-7704, CVE-2015-7705 Clients that receive a KoD should validate the origin timestamp field * CVE-2015-7691, CVE-2015-7692, CVE-2015-7702 Incomplete autokey data packet length checks - Use ntpq instead of deprecated ntpdc in start-ntpd . - Add a controlkey to ntp.conf to make the above work. - Improve runtime configuration: * Read keytype from ntp.conf * Don"t write ntp keys to syslog. - Don"t let keysdir lines in ntp.conf trigger the keys parser. - Fix the comment regarding addserver in ntp.conf . - Remove ntp.1.gz, it wasn"t installed anymore. - Remove ntp-4.2.7-rh-manpages.tar.gz and only keep ntptime.8.gz. The rest is partially irrelevant, partially redundant and potentially outdated . - Remove kod from the restrict line in ntp.conf . - Use SHA1 instead of MD5 for symmetric keys . - Require perl-Socket6 . - Fix incomplete backporting of rcntp ntptimemset.

Platform:
SUSE Linux Enterprise Server 11 SP4
Product:
ntp
Reference:
SUSE-SU-2015:2058-1
CVE-2015-7691
CVE-2015-7692
CVE-2015-7701
CVE-2015-7702
CVE-2015-7703
CVE-2015-7704
CVE-2015-7705
CVE-2015-7848
CVE-2015-7849
CVE-2015-7850
CVE-2015-7851
CVE-2015-7852
CVE-2015-7853
CVE-2015-7854
CVE-2015-7855
CVE-2015-7871
CVE    16
CVE-2015-7851
CVE-2015-7701
CVE-2015-7855
CVE-2015-7854
...

© SecPod Technologies