Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

SUSE 12-SP2-BCL: 2018:1765-2 Moderate: ntp DoS Issues Fix

suse
Calendar Grey October 18, 2018
Dist Suse Esm H88
An upgrade for openssl addresses various vulnerabilities, bolstering defense against recognized threats in Ubuntu Linux.
An update that solves 6 vulnerabilities and has two fixes is now available

Summary

This update for ntp fixes the following issues: - Update to 4.2.8p11 (bsc#1082210): * CVE-2016-1549: Sybil vulnerability: ephemeral association attack. While fixed in ntp-4.2.8p7, there are significant additional protections for this issue in 4.2.8p11. * CVE-2018-7182: ctl_getitem(): buffer read overrun leads to undefined behavior and information leak. (bsc#1083426) * CVE-2018-7170: Multiple authenticated ephemeral associations. (bsc#1083424) * CVE-2018-7184: Interleaved symmetric mode cannot recover from bad state. (bsc#1083422) * CVE-2018-7185: Unauthenticated packet can reset authenticated interleaved association. (bsc#1083420) * CVE-2018-7183: ntpq:decodearr() can write beyond its buffer limit.(bsc#1083417) - Don't use libevent's cached time stamps in sntp. (bsc#1077445)

References

#1077445 #1082063 #1082210 #1083417 #1083420

#1083422 #1083424 #1083426

Cross- CVE-2016-1549 CVE-2018-7170 CVE-2018-7182

CVE-2018-7183 CVE-2018-7184 CVE-2018-7185

Affected Products:

SUSE Linux Enterprise Server 12-SP2-BCL

https://www.suse.com/security/cve/CVE-2016-1549.html

https://www.suse.com/security/cve/CVE-2018-7170.html

https://www.suse.com/security/cve/CVE-2018-7182.html

https://www.suse.com/security/cve/CVE-2018-7183.html

https://www.suse.com/security/cve/CVE-2018-7184.html

https://www.suse.com/security/cve/CVE-2018-7185.html

https://bugzilla.suse.com/1077445

https://bugzilla.suse.com/1082063

https://bugzilla.suse.com/1082210

https://bugzilla.suse.com/1083417

https://bugzilla.suse.com/1083420

Announcement ID: SUSE-SU-2018:1765-2
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here