Gentoo Linux Security Advisory GLSA 200904-05
https://security.gentoo.org/
Severity: Normal
Title: ntp: Certificate validation error
Date: April 05, 2009
Bugs: #254098
ID: 200904-05
Synopsis
=======
An error in the OpenSSL certificate chain validation in ntp might allow
for spoofing attacks.
Background
=========
ntp contains the client and daemon implementations for the Network Time
Protocol.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-misc/ntp < 4.2.4_p6 >= 4.2.4_p6
==========
It has been reported that ntp incorrectly checks the return value of
the EVP_VerifyFinal(), a vulnerability related to CVE-2008-5077 (GLSA
200902-02).
Impact
=====
A remote...
style>.gentoo_availability{display:block;}
Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/107074_4c9dbbdde36eef04251a4ced7eac4df9 on line 11
Get the latest Linux and open source security news straight to your inbox.