Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Gentoo Linux Security Advisory GLSA 200904-05
https://security.gentoo.org/
Severity: Normal
Title: ntp: Certificate validation error
Date: April 05, 2009
Bugs: #254098
ID: 200904-05
Synopsis
=======
An error in the OpenSSL certificate chain validation in ntp might allow
for spoofing attacks.
Background
=========
ntp contains the client and daemon implementations for the Network Time
Protocol.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-misc/ntp < 4.2.4_p6 >= 4.2.4_p6
==========
It has been reported that ntp incorrectly checks the return value of
the EVP_VerifyFinal(), a vulnerability related to CVE-2008-5077 (GLSA
200902-02).
Impact
=====
A remote...
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.