Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 510
Alerts This Week
Warning Icon 1 510

openSUSE Leap 42.1: 2016:1329-1 Important: Ntp DoS Issues

opensuse
Calendar Grey May 18, 2016
Scroller Opensuse
A significant advisory for Fedora has been issued, targeting 10 security flaws within the kernel, thereby improving overall system protection and performance. Take action immediately!
An update that fixes 12 vulnerabilities is now available

Description

This update for ntp to 4.2.8p7 fixes the following issues:

* CVE-2016-1547, bsc#977459: Validate crypto-NAKs, AKA: CRYPTO-NAK DoS.

* CVE-2016-1548, bsc#977461: Interleave-pivot

* CVE-2016-1549, bsc#977451: Sybil vulnerability: ephemeral association

attack.

* CVE-2016-1550, bsc#977464: Improve NTP security against buffer

comparison timing attacks.

* CVE-2016-1551, bsc#977450: Refclock impersonation vulnerability

* CVE-2016-2516, bsc#977452: Duplicate IPs on unconfig directives will

cause an assertion botch in ntpd.

* CVE-2016-2517, bsc#977455: remote configuration trustedkey/

requestkey/controlkey values are not properly validated.

* CVE-2016-2518, bsc#977457: Crafted addpeer with hmode > 7 causes array

wraparound with MATCH_ASSOC.

* CVE-2016-2519, bsc#977458: ctl_getitem() return value not always checked.

* This update also improves the fixes for: CVE-2015-7704, CVE-2015-7705,

CVE-2015-7974

Bugs fixed:

- Restrict...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.1:

zypper in -t patch openSUSE-2016-599=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.1 (i586 x86_64):

ntp-4.2.8p7-21.1

ntp-debuginfo-4.2.8p7-21.1

ntp-debugsource-4.2.8p7-21.1

ntp-doc-4.2.8p7-21.1

References

https://www.suse.com/security/cve/CVE-2015-7704.html

https://www.suse.com/security/cve/CVE-2015-7705.html

https://www.suse.com/security/cve/CVE-2015-7974.html

https://www.suse.com/security/cve/CVE-2016-1547.html

https://www.suse.com/security/cve/CVE-2016-1548.html

https://www.suse.com/security/cve/CVE-2016-1549.html

https://www.suse.com/security/cve/CVE-2016-1550.html

https://www.suse.com/security/cve/CVE-2016-1551.html

https://www.suse.com/security/cve/CVE-2016-2516.html

https://www.suse.com/security/cve/CVE-2016-2517.html

https://www.suse.com/security/cve/CVE-2016-2518.html

https://www.suse.com/security/cve/CVE-2016-2519.html

https://bugzilla.suse.com/show_bug.cgi?id=957226

https://bugzilla.suse.com/show_bug.cgi?id=977446

https://bugzilla.suse.com/show_bug.cgi?id=977450

https://bugzilla.suse.com/show_bug.cgi?id=977451

https://bugzilla.suse.com/show_bug.cgi?id=977452

https://bugzilla.suse.com/show_bug.cgi?id=977455

https://bugzilla.suse.com/show_bug.cgi?id=977457

https://bugzilla.suse.com/show_bug.cgi?i...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:1329-1
Rating: important
Affected Products: openSUSE Leap 42.1 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.