Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
217

Oracle Linux 6 ELSA-2016-1141 Moderate: NTP Security Advisory

The following updated rpms for Oracle Linux 6 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2016-1141 https://linux.oracle.com/errata/ELSA-2016-1141.html The following updated rpms for Oracle Linux 6 have been uploaded to the Unbreakable Linux Network: i386: ntp-4.2.6p5-10.el6.1.i686.rpm ntp-doc-4.2.6p5-10.el6.1.noarch.rpm ntp-perl-4.2.6p5-10.el6.1.i686.rpm ntpdate-4.2.6p5-10.el6.1.i686.rpm x86_64: ntp-4.2.6p5-10.el6.1.x86_64.rpm ntp-doc-4.2.6p5-10.el6.1.noarch.rpm ntp-perl-4.2.6p5-10.el6.1.x86_64.rpm ntpdate-4.2.6p5-10.el6.1.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol6/SRPMS-updates/ntp-4.2.6p5-10.el6.1.src.rpm Description of changes: [4.2.6p5-10.el6_8.1] - don't allow spoofed packets to demobilize associations (CVE-2015-7979, CVE-2016-1547) - don't allow spoofed packet to enable symmetric interleaved mode (CVE-2016-1548) - check mode of new source in config command (CVE-2016-2518) - make MAC check resilient against timing attack (CVE-2016-1550) . The Oracle Linux Security Advisory ELSA-2016-1142 concerns vulnerabilities in the httpd service and provides essential patches. Discover further details here.. Oracle Linux, NTP Update, Security Advisory, Unbreakable Network, Moderate Severity. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 31, 2016 Important Oracle
87

Debian: DSA-3108-1 Critical: NTP Multiple Threats Fixed

Several vulnerabilities were discovered in the ntp package, an implementation of the Network Time Protocol. CVE-2014-9293 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3108-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Florian Weimer December 20, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ntp CVE ID : CVE-2014-9293 CVE-2014-9294 CVE-2014-9295 CVE-2014-9296 Debian Bug : 773576 Several vulnerabilities were discovered in the ntp package, an implementation of the Network Time Protocol. CVE-2014-9293 ntpd generated a weak key for its internal use, with full administrative privileges. Attackers could use this key to reconfigure ntpd (or to exploit other vulnerabilities). CVE-2014-9294 The ntp-keygen utility generated weak MD5 keys with insufficient entropy. CVE-2014-9295 ntpd had several buffer overflows (both on the stack and in the data section), allowing remote authenticated attackers to crash ntpd or potentially execute arbitrary code. CVE-2014-9296 The general packet processing function in ntpd did not handle an error case correctly. The default ntpd configuration in Debian restricts access to localhost (and possible the adjacent network in case of IPv6). Keys explicitly generated by "ntp-keygen -M" should be regenerated. For the stable distribution (wheezy), these problems have been fixed in version 1:4.2.6.p5+dfsg-2+deb7u1. We recommend that you upgrade your ntp packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Uncover essential improvements to the ntp software within Debian thattackle several vulnerabilities jeopardizing network time synchronization protocols.. NTP Security, Debian Update, Buffer Overflow, Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 20, 2014 Critical Debian
89

Fedora 9: 2009-5275 Critical: NTP Denial Of Service Issue And Crash

This update fixes a denial of service issue if autokey is enabled (default is disabled) and a crash in ntpq.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-5275 2009-05-20 21:38:23 -------------------------------------------------------------------------------- Name : ntp Product : Fedora 9 Version : 4.2.4p7 Release : 1.fc9 URL : http://www.ntp.org Summary : The NTP daemon and utilities Description : The Network Time Protocol (NTP) is used to synchronize a computer's time with another reference time source. This package includes ntpd (a daemon which continuously adjusts system time) and utilities used to query and configure the ntpd daemon. Perl scripts ntp-wait and ntptrace are in the ntp-perl package and the ntpdate program is in the ntpdate package. -------------------------------------------------------------------------------- Update Information: This update fixes a denial of service issue if autokey is enabled (default is disabled) and a crash in ntpq. -------------------------------------------------------------------------------- ChangeLog: * Tue May 19 2009 Miroslav Lichvar 4.2.4p7-1.fc9 - update to 4.2.4p7 (CVE-2009-1252, CVE-2009-0159) - don't log STA_MODE changes * Mon Jan 12 2009 Miroslav Lichvar 4.2.4p6-1.fc9 - update to 4.2.4p6 (CVE-2009-0021) * Wed Oct 8 2008 Miroslav Lichvar 4.2.4p5-2.fc9 - don't write drift file upon exit - run ntpq with full path in ntp-wait script * Fri Aug 29 2008 Miroslav Lichvar 4.2.4p5-1 - update to 4.2.4p5 - add support for fast interface updates * Mon Jul 28 2008 Miroslav Lichvar 4.2.4p4-7 - reload resolv.conf after temporary failure in name resolution (#456743) - use clock_gettime - make subpackages for perl scripts and ntpdate (#452097, #456116) -------------------------------------------------------------------------------- References: [ 1 ] Bug #499694 - CVE-2009-1252 ntp: remote arbitrary code execution vulnerability if autokeys is enabled https://bugzilla.redhat.com/show_bug.cgi?id=499694 [ 2 ] Bug #490617 - CVE-2009-0159 ntp: buffer overflow in ntpq https://bugzilla.redhat.com/show_bug.cgi?id=490617 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update ntp' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . This patch resolves the vulnerabilities causing service interruptions and crashes in the ntp module for Fedora 9. Use yum to install.. NTP Update,Fedora 9 Security,Denial Of Service,Network Time Protocol,ntp package. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 29, 2009 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here