MGASA-2015-0152
Dashboard / Vulnerabilities / MGASA-2015-0152
Summary: Updated ntp packages fix security vulnerabilities
Details: Updated ntp packages fix security vulnerabilities: The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP before 4.2.8p2 requires a correct MAC only if the MAC field has a nonzero length, which makes it easier for man-in-the-middle attackers to spoof packets by omitting the MAC (CVE-2015-1798). The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP before 4.2.8p2 performs state-variable updates upon receiving certain invalid packets, which makes it easier for man-in-the-middle attackers to cause a denial of service (synchronization loss) by spoofing the source IP address of a peer (CVE-2015-1799).
References: https://advisories.mageia.org/MGASA-2015-0152.html, https://bugs.mageia.org/show_bug.cgi?id=15646, http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_Vulnerabilities
Affected packages
Package
Name: ntp
Purl: pkg:rpm/mageia/ntp?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
