NTP was updated to 4.2.8p12 (bsc#1111853): - CVE-2018-12327: Fixed stack buffer overflow in the openhost() command-line call of NTPQ/NTPDC. (bsc#1098531) - CVE-2018-7170: Add further tweaks to improve the fix for the ephemeral association time spoofing additional protection (bsc#1083424) Please also see http://www.nwtime.org/network-time-foundation-publishes-ntp-4-2-8p12/ for more information. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Legacy Software 15: zypper in -t patch SUSE-SLE-Module-Legacy-15-2018-2431=1 Package List:
#1083424 #1098531 #1111853
Cross- CVE-2018-12327 CVE-2018-7170
Affected Products:
SUSE Linux Enterprise Module for Legacy Software 15
https://www.suse.com/security/cve/CVE-2018-12327.html
https://www.suse.com/security/cve/CVE-2018-7170.html
https://bugzilla.suse.com/1083424
https://bugzilla.suse.com/1098531
https://bugzilla.suse.com/1111853
Get the latest Linux and open source security news straight to your inbox.