Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE: 2016:1602-1 Important: NTP Critical Issues Resolved

suse
Calendar Grey June 17, 2016
Dist Suse Esm H88
An update for the ntp package addresses four vulnerabilities. Key security patches and essential updates released for SUSE operating systems.
An update that solves 5 vulnerabilities and has three fixes An update that solves 5 vulnerabilities and has three fixes An update that solves 5 vulnerabilities and has three fixes ...

Summary

ntp was updated to version 4.2.8p8 to fix five security issues. These security issues were fixed: - CVE-2016-4953: Bad authentication demobilizes ephemeral associations (bsc#982065). - CVE-2016-4954: Processing spoofed server packets (bsc#982066). - CVE-2016-4955: Autokey association reset (bsc#982067). - CVE-2016-4956: Broadcast interleave (bsc#982068). - CVE-2016-4957: CRYPTO_NAK crash (bsc#982064). These non-security issues were fixed: - Keep the parent process alive until the daemon has finished initialisation, to make sure that the PID file exists when the parent returns. - bsc#979302: Change the process name of the forking DNS worker process to avoid the impression that ntpd is started twice. - bsc#981422: Don't ignore SIGCHILD because it breaks wait(). Patch Instructions:

References

#979302 #981422 #982056 #982064 #982065 #982066

#982067 #982068

Cross- CVE-2016-4953 CVE-2016-4954 CVE-2016-4955

CVE-2016-4956 CVE-2016-4957

Affected Products:

SUSE OpenStack Cloud 5

SUSE Manager Proxy 2.1

SUSE Manager 2.1

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Server 11-SP2-LTSS

SUSE Linux Enterprise Debuginfo 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP2

https://www.suse.com/security/cve/CVE-2016-4953.html

https://www.suse.com/security/cve/CVE-2016-4954.html

https://www.suse.com/security/cve/CVE-2016-4955.html

https://www.suse.com/security/cve/CVE-2016-4956.html

https://www.suse.com/security/cve/CVE-2016-4957.html

https://bugzilla.suse.com/979302

https://bugzilla.suse.com/981422

https://bugzilla.suse.com/982056

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:1602-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here