Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 22: 2015-5761 Critical: NTP DoS Fix for CVE-2015-1799

fedora
Calendar Grey April 22, 2015
Dist Fedora Esm H88
Patch released for NTP in Fedora 22 tackling CVE-2015-1799 and CVE-2015-1798 vulnerabilities. Reinforce your system's robustness and security today.
Security fix for CVE-2015-1799, CVE-2015-1798, #1210324

Summary

The Network Time Protocol (NTP) is used to synchronize a computer's

time with another reference time source. This package includes ntpd

(a daemon which continuously adjusts system time) and utilities used

to query and configure the ntpd daemon.

Perl scripts ntp-wait and ntptrace are in the ntp-perl package,

ntpdate is in the ntpdate package and sntp is in the sntp package.

The documentation is in the ntp-doc package.

Update Information:

Security fix for CVE-2015-1799, CVE-2015-1798, #1210324

Change Log

References


[ 1 ] Bug #1199435 - CVE-2015-1799 ntp: authentication doesn't protect symmetric associations against DoS attacks https://bugzilla.redhat.com/show_bug.cgi?id=1199435 [ 2 ] Bug #1199430 - CVE-2015-1798 ntp: ntpd accepts unauthenticated packets with symmetric key crypto https://bugzilla.redhat.com/show_bug.cgi?id=1199430 [ 3 ] Bug #1210324 - ntp: ntp-keygen may generate non-random symmetric keys on big-endian systems https://bugzilla.redhat.com/show_bug.cgi?id=1210324

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update ntp' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: ntp
Product: Fedora 22
Version: 4.2.6p5
Release: 30.fc22
Summary: The NTP daemon and utilities

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here