Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE 2016:1912-1 Important: NTP Update Fixes DoS Threats

suse
Calendar Grey July 29, 2016
Scroller Suse
A significant SUSE upgrade delivers essential repairs for NTP, tackling various vulnerabilities such as denial of service threats.
An update that solves 43 vulnerabilities and has 9 fixes is An update that solves 43 vulnerabilities and has 9 fixes is An update that solves 43 vulnerabilities and has 9 fixes is ...

Summary

NTP was updated to version 4.2.8p8 to fix several security issues and to ensure the continued maintainability of the package. These security issues were fixed: * CVE-2016-4953: Bad authentication demobilized ephemeral associations (bsc#982065). * CVE-2016-4954: Processing spoofed server packets (bsc#982066). * CVE-2016-4955: Autokey association reset (bsc#982067). * CVE-2016-4956: Broadcast interleave (bsc#982068). * CVE-2016-4957: CRYPTO_NAK crash (bsc#982064). * CVE-2016-1547: Validate crypto-NAKs to prevent ACRYPTO-NAK DoS (bsc#977459). * CVE-2016-1548: Prevent the change of time of an ntpd client or denying service to an ntpd client by forcing it to change from basic client/server mode to interleaved symmetric mode (bsc#977461).

References

#782060 #784760 #905885 #910063 #916617 #920183

#920238 #920893 #920895 #920905 #924202 #926510

#936327 #943218 #943221 #944300 #951351 #951559

#951629 #952611 #957226 #962318 #962784 #962802

#962960 #962966 #962970 #962988 #962995 #963000

#963002 #975496 #977450 #977451 #977452 #977455

#977457 #977458 #977459 #977461 #977464 #979302

#981422 #982056 #982064 #982065 #982066 #982067

#982068 #988417 #988558 #988565

Cross- CVE-2015-1798 CVE-2015-1799 CVE-2015-5194

CVE-2015-5300 CVE-2015-7691 CVE-2015-7692

CVE-2015-7701 CVE-2015-7702 CVE-2015-7703

CVE-2015-7704 CVE-2015-7705 CVE-2015-7848

CVE-2015-7849 CVE-2015-7850 CVE-2015-7851

CVE-2015-7852 CVE-2015-7853 CVE-2015-7854

CVE-2015-7855 CVE-2015-7871 CVE-2015-...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:1912-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.