SUSE-SU-2015:0865-1
Dashboard / Vulnerabilities / SUSE-SU-2015:0865-1
SUSE-SU-2015:0865-1
Summary: Security update for ntp
Details: ntp was updated to fix two security related flaws as well as 'slew' mode handling for leap seconds. The following vulnerabilities were fixe: * ntpd could accept unauthenticated packets with symmetric key crypto. (CVE-2015-1798) * ntpd authentication did not protect symmetric associations against DoS attacks (CVE-2015-1799) * ntp-keygen may generate non-random symmetric keys on big-endian systems (bsc#928321, CVE-2015-3405). The following non-security issues were fixed: * Fix slew mode for leap seconds (bnc#918342).
References: https://www.suse.com/support/update/announcement/2015/suse-su-20150865-1/, https://bugzilla.suse.com/918342, https://bugzilla.suse.com/924202, https://bugzilla.suse.com/928321, https://www.suse.com/security/cve/CVE-2015-1798, https://www.suse.com/security/cve/CVE-2015-1799, https://www.suse.com/security/cve/CVE-2015-3405
Affected packages
Package
Name: ntp
Purl: pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Desktop%2012
Affected ranges
Type: ECOSYSTEM
Events:
