Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 34: 2023-0145 High: NTP Certificate Vulnerability Widespread

fedora
Calendar Grey January 26, 2009
Dist Fedora Esm H88
Fedora 10 enhances NTP to address security flaw in remote access. Update to rectify concerns with SSL/TLS cert chain verification.
This update fixes CVE-2009-0021: NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which ...

Summary

The Network Time Protocol (NTP) is used to synchronize a computer's

time with another reference time source. This package includes ntpd

(a daemon which continuously adjusts system time) and utilities used

to query and configure the ntpd daemon.

Perl scripts ntp-wait and ntptrace are in the ntp-perl package and

the ntpdate program is in the ntpdate package.

This update fixes CVE-2009-0021: NTP 4.2.4 before 4.2.4p5 and 4.2.5 before

4.2.5p150 does not properly check the return value from the OpenSSL

EVP_VerifyFinal function, which allows remote attackers to bypass validation of

the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys,

a similar vulnerability to CVE-2008-5077.

* Mon Jan 12 2009 Miroslav Lichvar 4.2.4p6-1

- update to 4.2.4p6 (CVE-2009-0021)

[ 1 ] Bug #476807 - CVE-2009-0021 ntp incorrectly checks for malformed signatures

https://bugzilla.redhat.com/show_bug.cgi?id=476807

su -c 'yum update ntp' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Product: Fedora 10
Version: 4.2.4p6
Release: 1.fc10
Summary: The NTP daemon and utilities

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here