Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

SUSE: 2016:1291-1 Important: NTP DoS Concerns and Fixes

suse
Calendar Grey May 12, 2016
Scroller Suse
An important patch for ntp resolves severe threats, notably DoS vulnerabilities found in SUSE operating systems.
An update that fixes 12 vulnerabilities is now available

Summary

This update for ntp to 4.2.8p7 fixes the following issues: * CVE-2016-1547, bsc#977459: Validate crypto-NAKs, AKA: CRYPTO-NAK DoS. * CVE-2016-1548, bsc#977461: Interleave-pivot * CVE-2016-1549, bsc#977451: Sybil vulnerability: ephemeral association attack. * CVE-2016-1550, bsc#977464: Improve NTP security against buffer comparison timing attacks. * CVE-2016-1551, bsc#977450: Refclock impersonation vulnerability * CVE-2016-2516, bsc#977452: Duplicate IPs on unconfig directives will cause an assertion botch in ntpd. * CVE-2016-2517, bsc#977455: remote configuration trustedkey/ requestkey/controlkey values are not properly validated. * CVE-2016-2518, bsc#977457: Crafted addpeer with hmode > 7 causes array wraparound with MATCH_ASSOC.

References

#957226 #977446 #977450 #977451 #977452 #977455

#977457 #977458 #977459 #977461 #977464

Cross- CVE-2015-7704 CVE-2015-7705 CVE-2015-7974

CVE-2016-1547 CVE-2016-1548 CVE-2016-1549

CVE-2016-1550 CVE-2016-1551 CVE-2016-2516

CVE-2016-2517 CVE-2016-2518 CVE-2016-2519

Affected Products:

SUSE Linux Enterprise Server 12-SP1

SUSE Linux Enterprise Desktop 12-SP1

https://www.suse.com/security/cve/CVE-2015-7704.html

https://www.suse.com/security/cve/CVE-2015-7705.html

https://www.suse.com/security/cve/CVE-2015-7974.html

https://www.suse.com/security/cve/CVE-2016-1547.html

https://www.suse.com/security/cve/CVE-2016-1548.html

https://www.suse.com/security/cve/CVE-2016-1549.html

https://www.suse.com/security/cve/CVE-2016-1550.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:1291-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.