Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora: 2009-5273 Critical: NTP 4.2.4p7 DoS Issue and Fix

fedora
Calendar Grey May 29, 2009
Dist Fedora Esm H88
This patch addresses a security vulnerability and system instability in ssh, improving the performance of Ubuntu 20.04.
This update fixes a denial of service issue if autokey is enabled (default is disabled) and a crash in ntpq.

Summary

The Network Time Protocol (NTP) is used to synchronize a computer's

time with another reference time source. This package includes ntpd

(a daemon which continuously adjusts system time) and utilities used

to query and configure the ntpd daemon.

Perl scripts ntp-wait and ntptrace are in the ntp-perl package and

the ntpdate program is in the ntpdate package.

Update Information:

This update fixes a denial of service issue if autokey is enabled (default is disabled) and a crash in ntpq.

Change Log

* Tue May 19 2009 Miroslav Lichvar 4.2.4p7-1 - update to 4.2.4p7 (CVE-2009-1252, CVE-2009-0159) - don't log STA_MODE changes - check status in condrestart (#481261) - convert COPYRIGHT to UTF-8 * Mon Jan 12 2009 Miroslav Lichvar 4.2.4p6-1 - update to 4.2.4p6 (CVE-2009-0021)

References


[ 1 ] Bug #499694 - CVE-2009-1252 ntp: remote arbitrary code execution vulnerability if autokeys is enabled https://bugzilla.redhat.com/show_bug.cgi?id=499694 [ 2 ] Bug #490617 - CVE-2009-0159 ntp: buffer overflow in ntpq https://bugzilla.redhat.com/show_bug.cgi?id=490617

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update ntp' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: ntp
Product: Fedora 10
Version: 4.2.4p7
Release: 1.fc10
Summary: The NTP daemon and utilities

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here