[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2009:309 -- Mandriva ntp

ID: oval:org.secpod.oval:def:300571Date: (C)2012-01-07   (M)2021-06-02
Class: PATCHFamily: unix




Multiple vulnerabilities has been found and corrected in ntp: Requesting peer information from a malicious remote time server may lead to an unexpected application termination or arbitrary code execution . A buffer overflow flaw was discovered in the ntpd daemon"s NTPv4 authentication code. If ntpd was configured to use public key cryptography for NTP packet authentication, a remote attacker could use this flaw to send a specially-crafted request packet that could crash ntpd . Packages for 2008.0 are being provided due to extended support for Corporate products. The updated packages have been patched to prevent this.

Platform:
Mandriva Linux 2008.0
Product:
ntp
Reference:
MDVSA-2009:309
CVE-2009-1252
CVE-2009-0159
CVE    2
CVE-2009-1252
CVE-2009-0159
CPE    1
cpe:/o:mandriva:linux:2008.0

© SecPod Technologies