Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
NTP could be made to crash.. =========================================================================Ubuntu Security Notice USN-4563-2 April 20, 2021 ntp vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS Summary: NTP could be made to crash. Software Description: - ntp: Network Time Protocol daemon and utility programs Details: USN-4563-1 fixed a vulnerability in NTP. This update provides the corresponding update for Ubuntu 20.04 LTS and Ubuntu 20.10. Original advisory details: It was discovered that the fix for CVE-2018-7182 introduced a NULL pointer dereference into NTP. An attacker could use this vulnerability to cause a denial of service (crash). Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: ntp 1:4.2.8p12+dfsg-3ubuntu4.20.10.1 ntpdate 1:4.2.8p12+dfsg-3ubuntu4.20.10.1 sntp 1:4.2.8p12+dfsg-3ubuntu4.20.10.1 Ubuntu 20.04 LTS: ntp 1:4.2.8p12+dfsg-3ubuntu4.20.04.1 ntpdate 1:4.2.8p12+dfsg-3ubuntu4.20.04.1 sntp 1:4.2.8p12+dfsg-3ubuntu4.20.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4563-2 https://ubuntu.com/security/notices/USN-4563-1 CVE-2019-8936 Package Information: https://launchpad.net/ubuntu/+source/ntp/1:4.2.8p12+dfsg-3ubuntu4.20.10.1 https://launchpad.net/ubuntu/+source/ntp/1:4.2.8p12+dfsg-3ubuntu4.20.04.1 . NTP exhibits susceptibility to failures in certain iterations of Ubuntu. Consult the security bulletin for comprehensiveinformation and necessary patches.. NTP Update, Ubuntu 20.04, Ubuntu 20.10, Denial Of Service. . LinuxSecurity.com Team
An update for ntp is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: ntp security update Advisory ID: RHSA-2020:1470-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:1470 Issue date: 2020-04-14 CVE Names: CVE-2018-12327 ==================================================================== 1. Summary: An update for ntp is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.6) - x86_64 Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6) - noarch, x86_64 Red Hat Enterprise Linux Server EUS (v. 7.6) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 7.6) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7) - aarch64, ppc64le, s390x Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7) - aarch64, noarch, ppc64le, s390x 3. Description: The Network Time Protocol (NTP) is used to synchronize a computer's time with another referenced time source. These packages include the ntpd service which continuously adjusts system time and utilities used to query and configure the ntpd service. Security Fix(es): * ntp: Stack-based buffer overflow in ntpq and ntpdc allows denial of service or code execution(CVE-2018-12327) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing this update, the ntpd daemon will restart automatically. 5. Bugs fixed (https://bugzilla.redhat.com/): 1593580 - CVE-2018-12327 ntp: Stack-based buffer overflow in ntpq and ntpdc allows denial of service or code execution 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v. 7.6): Source: ntp-4.2.6p5-28.el7_6.1.src.rpm x86_64: ntp-4.2.6p5-28.el7_6.1.x86_64.rpm ntp-debuginfo-4.2.6p5-28.el7_6.1.x86_64.rpm ntpdate-4.2.6p5-28.el7_6.1.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6): noarch: ntp-doc-4.2.6p5-28.el7_6.1.noarch.rpm ntp-perl-4.2.6p5-28.el7_6.1.noarch.rpm x86_64: ntp-debuginfo-4.2.6p5-28.el7_6.1.x86_64.rpm sntp-4.2.6p5-28.el7_6.1.x86_64.rpm Red Hat Enterprise Linux Server EUS (v. 7.6): Source: ntp-4.2.6p5-28.el7_6.1.src.rpm ppc64: ntp-4.2.6p5-28.el7_6.1.ppc64.rpm ntp-debuginfo-4.2.6p5-28.el7_6.1.ppc64.rpm ntpdate-4.2.6p5-28.el7_6.1.ppc64.rpm ppc64le: ntp-4.2.6p5-28.el7_6.1.ppc64le.rpm ntp-debuginfo-4.2.6p5-28.el7_6.1.ppc64le.rpm ntpdate-4.2.6p5-28.el7_6.1.ppc64le.rpm s390x: ntp-4.2.6p5-28.el7_6.1.s390x.rpm ntp-debuginfo-4.2.6p5-28.el7_6.1.s390x.rpm ntpdate-4.2.6p5-28.el7_6.1.s390x.rpm x86_64: ntp-4.2.6p5-28.el7_6.1.x86_64.rpm ntp-debuginfo-4.2.6p5-28.el7_6.1.x86_64.rpm ntpdate-4.2.6p5-28.el7_6.1.x86_64.rpm Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v.7): Source: ntp-4.2.6p5-28.el7_6.1.src.rpm aarch64: ntp-4.2.6p5-28.el7_6.1.aarch64.rpm ntp-debuginfo-4.2.6p5-28.el7_6.1.aarch64.rpm ntpdate-4.2.6p5-28.el7_6.1.aarch64.rpm ppc64le: ntp-4.2.6p5-28.el7_6.1.ppc64le.rpm ntp-debuginfo-4.2.6p5-28.el7_6.1.ppc64le.rpm ntpdate-4.2.6p5-28.el7_6.1.ppc64le.rpm s390x: ntp-4.2.6p5-28.el7_6.1.s390x.rpm ntp-debuginfo-4.2.6p5-28.el7_6.1.s390x.rpm ntpdate-4.2.6p5-28.el7_6.1.s390x.rpm Red Hat Enterprise Linux Server Optional EUS (v. 7.6): noarch: ntp-doc-4.2.6p5-28.el7_6.1.noarch.rpm ntp-perl-4.2.6p5-28.el7_6.1.noarch.rpm ppc64: ntp-debuginfo-4.2.6p5-28.el7_6.1.ppc64.rpm sntp-4.2.6p5-28.el7_6.1.ppc64.rpm ppc64le: ntp-debuginfo-4.2.6p5-28.el7_6.1.ppc64le.rpm sntp-4.2.6p5-28.el7_6.1.ppc64le.rpm s390x: ntp-debuginfo-4.2.6p5-28.el7_6.1.s390x.rpm sntp-4.2.6p5-28.el7_6.1.s390x.rpm x86_64: ntp-debuginfo-4.2.6p5-28.el7_6.1.x86_64.rpm sntp-4.2.6p5-28.el7_6.1.x86_64.rpm Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7): aarch64: ntp-debuginfo-4.2.6p5-28.el7_6.1.aarch64.rpm sntp-4.2.6p5-28.el7_6.1.aarch64.rpm noarch: ntp-doc-4.2.6p5-28.el7_6.1.noarch.rpm ntp-perl-4.2.6p5-28.el7_6.1.noarch.rpm ppc64le: ntp-debuginfo-4.2.6p5-28.el7_6.1.ppc64le.rpm sntp-4.2.6p5-28.el7_6.1.ppc64le.rpm s390x: ntp-debuginfo-4.2.6p5-28.el7_6.1.s390x.rpm sntp-4.2.6p5-28.el7_6.1.s390x.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-12327 https://access.redhat.com/security/updates/classification/#low 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXpX189zjgjWX9erEAQiHwg//ZpvjQ1n+z1UTHcWnXF8wSdCY7Bxkk0Xo bL1rkCPEOqc6j91Bx21zYne4MjGEKxGyyPNVQJ6szAG/IBt1OXe19iO+lzsYcfPr dSYRaRmv6x1Ak/yLzN2VIS1v2/V2s0ZLVTkO65h/0znNkz9YqJlOGDkG1qG4x2lH bnOgFx8lwFts29JvkFIhvo37fa1yu+CUqwMrsW3x10MBYeir0N355Sw9PyXn3vbv 0YMWVMRrRlgBw2nTujUt3q6eXpBP9z7jJkhaO2yooPvwXM6AnSGhhhcDk8i43qIM 3a2AORXciBxaZ7pmw0CumiTZVhJZ/X1NdDXJ5w4z/VDBfILA5hpe2WnGztoHyIy3 05Th6+9WXqsChAL3jzLcpMADwDKXPNbjJS3LA/CWmFjI5T3n3nfcfPRG5fAtV2Kk M1HjAeMPRyoz6EI9dlk8MDhBmmJPi/+RTmDV/vFzdntaLBAja4fDYzbwgiJuFtFP rpqG+tpb4qC3RVY9LfvyGic5zMyMhEfjyVp4IcIQBqzMVprb6q/pKAdS7aDhxtDb cI3mDVQTKmU9/9+D6ES50+hiImf3hLkNruEt6KmnPdOxBO7IINVm7Y0heoKarQ++ bT8sDKppcg5vFoRmoLUFMbfa91GLTpV+JLaU8F/VQTNaEpYsBihaGPNpEPOWNd8D RYYqzIy6m6s=Nb06 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
ntp: Stack-based buffer overflow in ntpq and ntpdc allows denial of service or code execution (CVE-2018-12327) SL7 x86_64 ntpdate-4.2.6p5-29.el7.x86_64.rpm ntp-4.2.6p5-29.el7.x86_64.rpm ntp-doc-4.2.6p5-29.el7.noarch.rpm sntp-4.2.6p5-29.el7.x86_64.rpm ntp-perl-4.2.6p5-29.el7.noarch.rpm ntp-debuginfo-4.2.6p5-29.el7.x86_64.rpm noarch ntp-doc-4.2.6p5-29.el7.noarch. [More...]. Synopsis: Low: ntp security, bug fix, and enhancement update Advisory ID: SLSA-2019:2077-1 Issue Date: 2019-08-06 CVE Numbers: CVE-2018-12327 -- Security Fix(es): * ntp: Stack-based buffer overflow in ntpq and ntpdc allows denial of service or code execution (CVE-2018-12327) -- SL7 x86_64 ntpdate-4.2.6p5-29.el7.x86_64.rpm ntp-4.2.6p5-29.el7.x86_64.rpm ntp-doc-4.2.6p5-29.el7.noarch.rpm sntp-4.2.6p5-29.el7.x86_64.rpm ntp-perl-4.2.6p5-29.el7.noarch.rpm ntp-debuginfo-4.2.6p5-29.el7.x86_64.rpm noarch ntp-doc-4.2.6p5-29.el7.noarch.rpm ntp-perl-4.2.6p5-29.el7.noarch.rpm - Scientific Linux Development Team . Minor ntp security patch rollout featuring bug remediation for Scientific Linux SL7, aimed at mitigating denial of service threats.. ntp Security, Stack-based Overflow, Scientific Linux Update, Denial of Service. . Severity: Low. LinuxSecurity.com Team
New ntp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] ntp (SSA:2019-067-01) New ntp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/ntp-4.2.8p13-i586-1_slack14.2.txz: Upgraded. This release fixes a bug that allows an attacker with access to an explicitly trusted source to send a crafted malicious mode 6 (ntpq) packet that can trigger a NULL pointer dereference, crashing ntpd. It also provides 17 other bugfixes and 1 other improvement. For more information, see: https://www.cve.org/CVERecord?id=CVE-2019-8936 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.0: Updated package for Slackware x86_64 14.0: Updated package for Slackware 14.1: Updated package for Slackware x86_64 14.1: Updated package for Slackware 14.2: Updated package for Slackware x86_64 14.2: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.0 package: 5f793a49c125f84588f35f3188bc66a5 ntp-4.2.8p13-i486-1_slack14.0.txz Slackware x86_64 14.0 package: 7e267fa9417e49dc12419be62dde2fbe ntp-4.2.8p13-x86_64-1_slack14.0.txz Slackware 14.1 package: ad9f93989093f0e000a4f412cee01104 ntp-4.2.8p13-i486-1_slack14.1.txz Slackware x86_64 14.1 package: 57959b70be4e6aa471ccff83d25ba172 ntp-4.2.8p13-x86_64-1_slack14.1.txz Slackware 14.2 package: a88168ed545465b2ec789127c83d70be ntp-4.2.8p13-i586-1_slack14.2.txz Slackware x86_64 14.2package: 7756b9440efee21ff1f61b94beaafa66 ntp-4.2.8p13-x86_64-1_slack14.2.txz Slackware -current package: a6498ca0614e59cfc456077ffd4cdf16 n/ntp-4.2.8p13-i586-1.txz Slackware x86_64 -current package: c028aff712c76be79c4a85b05884f988 n/ntp-4.2.8p13-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg ntp-4.2.8p13-i586-1_slack14.2.txz Then, restart the NTP daemon: # sh /etc/rc.d/rc.ntpd restart +-----+ . Latest ntp updates for Slackware 14.x address a vulnerability causing ntpd to fail. Elevate your system's security by updating your packages.. NTP Update, Slackware Security, DoS Fix. . Severity: Important. LinuxSecurity.com Team
An update for ntp is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: ntp security update Advisory ID: RHSA-2018:3853-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2018:3853 Issue date: 2018-12-19 CVE Names: CVE-2018-12327 ==================================================================== 1. Summary: An update for ntp is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux HPC Node EUS (v. 6.7) - x86_64 Red Hat Enterprise Linux HPC Node Optional EUS (v. 6.7) - noarch, x86_64 Red Hat Enterprise Linux Server EUS (v. 6.7) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 6.7) - i386, noarch, ppc64, s390x, x86_64 3. Description: The Network Time Protocol (NTP) is used to synchronize a computer's time with another referenced time source. These packages include the ntpd service which continuously adjusts system time and utilities used to query and configure the ntpd service. Security Fix(es): * ntp: Stack-based buffer overflow in ntpq and ntpdc allows denial of service or code execution (CVE-2018-12327) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how toapply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing this update, the ntpd daemon will restart automatically. 5. Bugs fixed (https://bugzilla.redhat.com/): 1593580 - CVE-2018-12327 ntp: Stack-based buffer overflow in ntpq and ntpdc allows denial of service or code execution 6. Package List: Red Hat Enterprise Linux HPC Node EUS (v. 6.7): Source: ntp-4.2.6p5-5.el6_7.6.src.rpm x86_64: ntp-4.2.6p5-5.el6_7.6.x86_64.rpm ntp-debuginfo-4.2.6p5-5.el6_7.6.x86_64.rpm ntpdate-4.2.6p5-5.el6_7.6.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional EUS (v. 6.7): noarch: ntp-doc-4.2.6p5-5.el6_7.6.noarch.rpm x86_64: ntp-debuginfo-4.2.6p5-5.el6_7.6.x86_64.rpm ntp-perl-4.2.6p5-5.el6_7.6.x86_64.rpm Red Hat Enterprise Linux Server EUS (v. 6.7): Source: ntp-4.2.6p5-5.el6_7.6.src.rpm i386: ntp-4.2.6p5-5.el6_7.6.i686.rpm ntp-debuginfo-4.2.6p5-5.el6_7.6.i686.rpm ntpdate-4.2.6p5-5.el6_7.6.i686.rpm ppc64: ntp-4.2.6p5-5.el6_7.6.ppc64.rpm ntp-debuginfo-4.2.6p5-5.el6_7.6.ppc64.rpm ntpdate-4.2.6p5-5.el6_7.6.ppc64.rpm s390x: ntp-4.2.6p5-5.el6_7.6.s390x.rpm ntp-debuginfo-4.2.6p5-5.el6_7.6.s390x.rpm ntpdate-4.2.6p5-5.el6_7.6.s390x.rpm x86_64: ntp-4.2.6p5-5.el6_7.6.x86_64.rpm ntp-debuginfo-4.2.6p5-5.el6_7.6.x86_64.rpm ntpdate-4.2.6p5-5.el6_7.6.x86_64.rpm Red Hat Enterprise Linux Server Optional EUS (v. 6.7): i386: ntp-debuginfo-4.2.6p5-5.el6_7.6.i686.rpm ntp-perl-4.2.6p5-5.el6_7.6.i686.rpm noarch: ntp-doc-4.2.6p5-5.el6_7.6.noarch.rpm ppc64: ntp-debuginfo-4.2.6p5-5.el6_7.6.ppc64.rpm ntp-perl-4.2.6p5-5.el6_7.6.ppc64.rpm s390x: ntp-debuginfo-4.2.6p5-5.el6_7.6.s390x.rpm ntp-perl-4.2.6p5-5.el6_7.6.s390x.rpm x86_64: ntp-debuginfo-4.2.6p5-5.el6_7.6.x86_64.rpm ntp-perl-4.2.6p5-5.el6_7.6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7.References: https://access.redhat.com/security/cve/CVE-2018-12327 https://access.redhat.com/security/updates/classification#low 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXBqCC9zjgjWX9erEAQhM+A/5Ac4HjB2bNQ0rW0YzHGRrFXIWfJo1qEbv QYp4tLedYksgPIWrAXc9OGSvAC1c3kYhatViw2K+5yr/FX71gQ7UUSYpxrAGx3/F G59kLAkR+P9uAq/XsgJZdf6sg4AQOVV+vQWg8umERE4I9wXRkTU/vV8a+gkNq0u3 4oq5COZZ+svXNf9rHBare/e3h2rm8i/6VoJ82YKkRiIH20IWACvYHnqdJ44pDWTc 9Tn0vd+odcuL3klcoxlRGUsk8nZqIWMTuXubrEt3ELj8msbS32zkPLJtwHKxbEJp FFQRMvy+3fXuVWaNOt/xtYj/0y41/9orsR4tQfOrKbBYzIFN6050JHLc/7X1PTCh NlZe/X1oJIGY86SS1yIEIgBqK5msK9Y+sFzCgPMJj5Szgo8kipE9CMyc+APtMOOi NJwbBr0eRrVOk7vvoO5U9wlJ6QcIzw5fcqZ+nHq66VM77D5jJneslwtX1bhI9yJt FF+QkfQd2udkeQEU3ur08up9cqyYUo2vytxZTWf2O+siVFTU71xKj2vwbbGbM8Nc S7PYOKMHHO4CbMH1DC6dWdPed9mh110CXqp7SnPQAJj6xqikRQK/ZEDp6E/nZJMH qSXqWoZ1j9n5vuOXNZFI1hr2ZiXs2WdD8c8tTGoIJlHNvB38RBV7pj+XPLO6VAEJ UGFrDfglxq4=tTdl -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update that solves two vulnerabilities and has one errata is now available. . SUSE Security Update: Security update for ntp ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:3386-1 Rating: moderate References: #1083424 #1098531 #1111853 Cross-References: CVE-2018-12327 CVE-2018-7170 Affected Products: SUSE Linux Enterprise Module for Legacy Software 15 ______________________________________________________________________________ An update that solves two vulnerabilities and has one errata is now available. Description: NTP was updated to 4.2.8p12 (bsc#1111853): - CVE-2018-12327: Fixed stack buffer overflow in the openhost() command-line call of NTPQ/NTPDC. (bsc#1098531) - CVE-2018-7170: Add further tweaks to improve the fix for the ephemeral association time spoofing additional protection (bsc#1083424) Please also see http://www.nwtime.org/network-time-foundation-publishes-ntp-4-2-8p12/ for more information. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Legacy Software 15: zypper in -t patch SUSE-SLE-Module-Legacy-15-2018-2431=1 Package List: - SUSE Linux Enterprise Module for Legacy Software 15 (aarch64 ppc64le s390x x86_64): ntp-4.2.8p12-4.3.2 ntp-debuginfo-4.2.8p12-4.3.2 ntp-debugsource-4.2.8p12-4.3.2 References: https://www.suse.com/security/cve/CVE-2018-12327.html https://www.suse.com/security/cve/CVE-2018-7170.html https://bugzilla.suse.com/1083424 https://bugzilla.suse.com/1098531 https://bugzilla.suse.com/1111853 _______________________________________________ sle-security-updates mailing list
An update that solves 5 vulnerabilities and has four fixes An update that solves 5 vulnerabilities and has four fixes An update that solves 5 vulnerabilities and has four fixes is now available. is now available.. openSUSE Security Update: Security update for ntp ______________________________________________________________________________ Announcement ID: openSUSE-SU-2016:1636-1 Rating: important References: #979302 #979981 #981422 #982056 #982064 #982065 #982066 #982067 #982068 Cross-References: CVE-2016-4953 CVE-2016-4954 CVE-2016-4955 CVE-2016-4956 CVE-2016-4957 Affected Products: openSUSE Leap 42.1 ______________________________________________________________________________ An update that solves 5 vulnerabilities and has four fixes is now available. Description: ntp was updated to version 4.2.8p8 to fix five security issues. These security issues were fixed: - CVE-2016-4953: Bad authentication demobilizes ephemeral associations (bsc#982065). - CVE-2016-4954: Processing spoofed server packets (bsc#982066). - CVE-2016-4955: Autokey association reset (bsc#982067). - CVE-2016-4956: Broadcast interleave (bsc#982068). - CVE-2016-4957: CRYPTO_NAK crash (bsc#982064). These non-security issues were fixed: - Keep the parent process alive until the daemon has finished initialisation, to make sure that the PID file exists when the parent returns. - bsc#979302: Change the process name of the forking DNS worker process to avoid the impression that ntpd is started twice. - bsc#981422: Don't ignore SIGCHILD because it breaks wait(). - bsc#979981: ntp-wait does not accept fractional seconds, so use 1 instead of 0.2 in ntp-wait.service. - Separate the creation of ntp.keys and key #1 in it to avoid problems when upgrading installations that have the file, but no key #1, which is needed e.g. by "rcntp addserver". This update was imported fromthe SUSE:SLE-12-SP1:Update update project. Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.1: zypper in -t patch openSUSE-2016-750=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.1 (i586 x86_64): ntp-4.2.8p8-24.1 ntp-debuginfo-4.2.8p8-24.1 ntp-debugsource-4.2.8p8-24.1 ntp-doc-4.2.8p8-24.1 References: https://www.suse.com/security/cve/CVE-2016-4953.html https://www.suse.com/security/cve/CVE-2016-4954.html https://www.suse.com/security/cve/CVE-2016-4955.html https://www.suse.com/security/cve/CVE-2016-4956.html https://www.suse.com/security/cve/CVE-2016-4957.html https://bugzilla.suse.com/979302 https://bugzilla.suse.com/979981 https://bugzilla.suse.com/981422 https://bugzilla.suse.com/982056 https://bugzilla.suse.com/982064 https://bugzilla.suse.com/982065 https://bugzilla.suse.com/982066 https://bugzilla.suse.com/982067 https://bugzilla.suse.com/982068 . A vital upgrade for openSUSE ntp addresses numerous significant vulnerabilities and boosts overall system stability and efficiency.. openSUSE, NTP Patch, Security Update, System Exploits. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 6 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2016-1141 https://linux.oracle.com/errata/ELSA-2016-1141.html The following updated rpms for Oracle Linux 6 have been uploaded to the Unbreakable Linux Network: i386: ntp-4.2.6p5-10.el6.1.i686.rpm ntp-doc-4.2.6p5-10.el6.1.noarch.rpm ntp-perl-4.2.6p5-10.el6.1.i686.rpm ntpdate-4.2.6p5-10.el6.1.i686.rpm x86_64: ntp-4.2.6p5-10.el6.1.x86_64.rpm ntp-doc-4.2.6p5-10.el6.1.noarch.rpm ntp-perl-4.2.6p5-10.el6.1.x86_64.rpm ntpdate-4.2.6p5-10.el6.1.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol6/SRPMS-updates/ntp-4.2.6p5-10.el6.1.src.rpm Description of changes: [4.2.6p5-10.el6_8.1] - don't allow spoofed packets to demobilize associations (CVE-2015-7979, CVE-2016-1547) - don't allow spoofed packet to enable symmetric interleaved mode (CVE-2016-1548) - check mode of new source in config command (CVE-2016-2518) - make MAC check resilient against timing attack (CVE-2016-1550) . The Oracle Linux Security Advisory ELSA-2016-1142 concerns vulnerabilities in the httpd service and provides essential patches. Discover further details here.. Oracle Linux, NTP Update, Security Advisory, Unbreakable Network, Moderate Severity. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.