Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
198

Arch Linux: ASA-202310-15 Significant NTP Security Vulnerability

The package ntp before version 4.2.8-1 is vulnerable to multiple issues including but not limited to arbitrary code execution, denial of service and weak key generation. . Arch Linux Security Advisory ASA-201412-24 ========================================= Severity: Critical Date : 2014-12-22 CVE-ID : CVE-2014-9293 CVE-2014-9294 CVE-2014-9295 CVE-2014-9296 Package : ntp Type : multiple issues Remote : Yes Link : https://wiki.archlinux.org/title/CVE-2014 Summary ====== The package ntp before version 4.2.8-1 is vulnerable to multiple issues including but not limited to arbitrary code execution, denial of service and weak key generation. Resolution ========= Upgrade to 4.2.8-1. # pacman -Syu "ntp> =4.2.8-1" The problems have been fixed upstream in version 4.2.8. Workaround ========= None. Description ========== Keys explicitly generated by "ntp-keygen -M" should be regenerated. - CVE-2014-9293 (weak key generation) ntpd generated a weak key for its internal use, with full administrative privileges. Attackers could use this key to reconfigure ntpd (or to exploit other vulnerabilities). - CVE-2014-9294 (weak key generation) The ntp-keygen utility generated weak MD5 keys with insufficient entropy, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack. - CVE-2014-9295 (arbitrary code execution) Multiple stack-based buffer overflows in allow remote attackers to execute arbitrary code via a crafted packet, related to (1) the crypto_recv function when the Autokey Authentication feature is used, (2) the ctl_putdata function, and (3) the configure function. - CVE-2014-9296 (unintended association change) The receive function in ntp_proto.c continues to execute after detecting a certain authentication error, which might allow remote attackers to trigger an unintended association change via crafted packets. Impact ===== A remote attacker is able to craft packets leading to arbitrarycode execution, denial of service or make use of a weak key generation flaw to perform cryptographic attacks against the authentication. References ========= https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9293 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9294 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9295 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9296 https://bugs.ntp.org/show_bug.cgi?id=2665 https://bugs.ntp.org/show_bug.cgi?id=2666 https://bugs.ntp.org/show_bug.cgi?id=2667 https://bugs.ntp.org/show_bug.cgi?id=2670 . The Arch Linux Security Announcement ASA-201501-30 reveals crucial vulnerabilities in OpenSSL tied to memory corruption and poor cryptographic standards, along with a provided fix. Arch Linux Advisory, NTP Security Issues, Critical Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 22, 2014 Critical ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here