Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE 11 SP1 LTSS: SUSE-SU-2015:0259-3 Important NTP Update

suse
Calendar Grey February 16, 2015
Dist Suse Esm H88
Critical notice regarding ntp servers addresses various vulnerabilities. Strengthen your system's defense by applying updates promptly.
An update that fixes four vulnerabilities is now available

Summary

ntp has been updated to fix four security issues: * CVE-2014-9294: ntp-keygen used a weak RNG seed, which made it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack. (bsc#910764) * CVE-2014-9293: The config_auth function, when an auth key is not configured, improperly generated a key, which made it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack. (bsc#910764) * CVE-2014-9298: ::1 can be spoofed on some operating systems, so ACLs based on IPv6 ::1 addresses could be bypassed. (bsc#910764) * CVE-2014-9297: vallen is not validated in several places in ntp_crypto.c, leading to potential information leak. (bsc#910764) Security Issues: * CVE-2014-9294

References

#910764 #911792

Cross- CVE-2014-9293 CVE-2014-9294 CVE-2014-9297

CVE-2014-9298

Affected Products:

SUSE Linux Enterprise Server 11 SP1 LTSS

https://www.suse.com/security/cve/CVE-2014-9293.html

https://www.suse.com/security/cve/CVE-2014-9294.html

https://www.suse.com/security/cve/CVE-2014-9297.html

https://www.suse.com/security/cve/CVE-2014-9298.html

https://bugzilla.suse.com/show_bug.cgi?id=910764

https://bugzilla.suse.com/show_bug.cgi?id=911792

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0259-3
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here