Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Ubuntu 12.04 ESM: USN-3707-2 Moderate: NTP Service Denial of Service

Ubuntu Large Esm H500
Several security issues were fixed in NTP.
=========================================================================Ubuntu Security Notice USN-3707-2
January 23, 2019

ntp vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 ESM

Summary:

Several security issues were fixed in NTP.

Software Description:
- ntp: Network Time Protocol daemon and utility programs

Details:

USN-3707-1 and USN-3349-1 fixed several vulnerabilities in NTP. This
update provides the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

 Miroslav Lichvar discovered that NTP incorrectly handled certain
 spoofed addresses when performing rate limiting. A remote attacker
 could possibly use this issue to perform a denial of service.
 (CVE-2016-7426)

 Matthew Van Gundy discovered that NTP incorrectly handled certain
 crafted broadcast mode packets. A remote attacker could possibly use
 this issue to perform a denial of service. 
 (CVE-2016-7427, CVE-2016-7428)

 Matthew Van Gundy discovered that NTP incorrectly handled certain
 control mode packets. A remote attacker could use this issue to set or
 unset traps. (CVE-2016-9310)

 Matthew Van Gundy discovered that NTP incorrectly handled the trap
 service. A remote attacker could possibly use this issue to cause NTP
 to crash, resulting in a denial of service. (CVE-2016-9311)

 It was discovered that the NTP legacy DPTS refclock driver incorrectly
 handled the /dev/datum device. A local attacker could possibly use
 this issue to cause a denial of service. (CVE-2017-6462)

 It was discovered that NTP incorrectly handled certain invalid
 settings in a :config directive. A remote authenticated user could
 possibly use this issue to cause NTP to crash, resulting in a denial
 of service. (CVE-2017-6463)

 Michael Macnair discovered that NTP incorrectly handled certain
 responses. A remote attacker could possibly use this issue to execute
 arbitrary code. (CVE-2018-7183)

 Miroslav Lichvar discovered that NTP incorrectly handled certain
 zero-origin timestamps. A remote attacker could possibly use this
 issue to cause a denial of service. (CVE-2018-7185)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  ntp                             1:4.2.6.p3+dfsg-1ubuntu3.12

In general, a standard system update will make all the necessary
changes.

References:
  https://ubuntu.com/security/notices/USN-3707-2
  https://ubuntu.com/security/notices/USN-3707-1
  CVE-2016-7426, CVE-2016-7427, CVE-2016-7428, CVE-2016-9310,
  CVE-2016-9311, CVE-2017-6462, CVE-2017-6463, CVE-2018-7183,
  CVE-2018-7185

Ubuntu 12.04 ESM: USN-3707-2 Moderate: NTP Service Denial of Service

ubuntu
Calendar Grey January 23, 2019
Dist Ubuntu Esm H88
Important patch for Ubuntu 12.04 ESM targeting various NTP vulnerabilities impacting reliability and performance.
Several security issues were fixed in NTP.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM:   ntp                             1:4.2.6.p3+dfsg-1ubuntu3.12 In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-3707-2

  https://ubuntu.com/security/notices/USN-3707-1

  CVE-2016-7426, CVE-2016-7427, CVE-2016-7428, CVE-2016-9310,

  CVE-2016-9311, CVE-2017-6462, CVE-2017-6463, CVE-2018-7183,

  CVE-2018-7185

January 23, 2019

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here