Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
198

Arch Linux 2016: ASA-201601-19 Medium Severity: NTP Time Alteration

The package ntp before version 4.2.8.p5-1 is vulnerable to time alteration. . Arch Linux Security Advisory ASA-201601-19 ========================================= Severity: Medium Date : 2016-01-17 CVE-ID : CVE-2015-5300 Package : ntp Type : time alteration Remote : Yes Link : https://wiki.archlinux.org/title/CVE Summary ====== The package ntp before version 4.2.8.p5-1 is vulnerable to time alteration. Resolution ========= Upgrade to 4.2.8.p5-1. # pacman -Syu "ntp> =4.2.8.p5-1" The problem has been fixed upstream in version 4.2.8.p5. Workaround ========= Removing -g from the ntpd startup options limits the time modification to 900s per attack. This can be done by editing the ExecStart line of the /usr/lib/systemd/system/ntpd.service file to remove the -g option, then issuing: # systemctl daemon-reload # systemctl restart ntpd Description ========== If ntpd is always started with the -g option, which is common and against long-standing recommendation, and if at the moment ntpd is restarted an attacker can immediately respond to enough requests from enough sources trusted by the target, which is difficult and not common, there is a window of opportunity where the attacker can cause ntpd to set the time to an arbitrary value. Similarly, if an attacker is able to respond to enough requests from enough sources trusted by the target, the attacker can cause ntpd to abort and restart, at which point it can tell the target to set the time to an arbitrary value if and only if ntpd was re-started against long-standing recommendation with the -g flag, or if ntpd was not given the -g flag, the attacker can move the target system's time by at most 900 seconds' time per attack. Impact ===== As the ntpd default startup options on Arch contain -g, a remote attacker might be able to alter the system time to an arbitrary value, bypassing checks based on the time, like for example X.509 certificates expirationdates. References ========= https://access.redhat.com/security/cve/CVE-2015-5300 http://www.ntp.org/support/securitynotice/ntpbug2956/ https://www.cs.bu.edu/~goldbe/NTPattack.html . Arch Linux Security Bulletin on NTP time modification flaw specifics medium risk CVE-2015-5300 remedy and enhancements.. Arch Linux, NTP Patch, Time Attack, Medium Severity. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Jan 17, 2016 Medium ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here