SUSE-SU-2015:2058-1
Dashboard / Vulnerabilities / SUSE-SU-2015:2058-1
SUSE-SU-2015:2058-1
Summary: Security update for ntp
Details: This ntp update provides the following security and non security fixes: - Update to 4.2.8p4 to fix several security issues (bsc#951608): * CVE-2015-7871: NAK to the Future: Symmetric association authentication bypass via crypto-NAK * CVE-2015-7855: decodenetnum() will ASSERT botch instead of returning FAIL on some bogus values * CVE-2015-7854: Password Length Memory Corruption Vulnerability * CVE-2015-7853: Invalid length data provided by a custom refclock driver could cause a buffer overflow * CVE-2015-7852 ntpq atoascii() Memory Corruption Vulnerability * CVE-2015-7851 saveconfig Directory Traversal Vulnerability * CVE-2015-7850 remote config logfile-keyfile * CVE-2015-7849 trusted key use-after-free * CVE-2015-7848 mode 7 loop counter underrun * CVE-2015-7701 Slow memory leak in CRYPTO_ASSOC * CVE-2015-7703 configuration directives 'pidfile' and 'driftfile' should only be allowed locally * CVE-2015-7704, CVE-2015-7705 Clients that receive a KoD should validate the origin timestamp field * CVE-2015-7691, CVE-2015-7692, CVE-2015-7702 Incomplete autokey data packet length checks - Use ntpq instead of deprecated ntpdc in start-ntpd (bnc#936327). - Add a controlkey to ntp.conf to make the above work. - Improve runtime configuration: * Read keytype from ntp.conf * Don't write ntp keys to syslog. - Don't let 'keysdir' lines in ntp.conf trigger the 'keys' parser. - Fix the comment regarding addserver in ntp.conf (bnc#910063). - Remove ntp.1.gz, it wasn't installed anymore. - Remove ntp-4.2.7-rh-manpages.tar.gz and only keep ntptime.8.gz. The rest is partially irrelevant, partially redundant and potentially outdated (bsc#942587). - Remove 'kod' from the restrict line in ntp.conf (bsc#944300). - Use SHA1 instead of MD5 for symmetric keys (bsc#905885). - Require perl-Socket6 (bsc#942441). - Fix incomplete backporting of 'rcntp ntptimemset'.
References: https://www.suse.com/support/update/announcement/2015/suse-su-20152058-1/, https://bugzilla.suse.com/905885, https://bugzilla.suse.com/910063, https://bugzilla.suse.com/936327, https://bugzilla.suse.com/942441, https://bugzilla.suse.com/942587, https://bugzilla.suse.com/944300, https://bugzilla.suse.com/951608, https://www.suse.com/security/cve/CVE-2015-7691, https://www.suse.com/security/cve/CVE-2015-7692, https://www.suse.com/security/cve/CVE-2015-7701, https://www.suse.com/security/cve/CVE-2015-7702, https://www.suse.com/security/cve/CVE-2015-7703, https://www.suse.com/security/cve/CVE-2015-7704, https://www.suse.com/security/cve/CVE-2015-7705, https://www.suse.com/security/cve/CVE-2015-7848, https://www.suse.com/security/cve/CVE-2015-7849, https://www.suse.com/security/cve/CVE-2015-7850, https://www.suse.com/security/cve/CVE-2015-7851, https://www.suse.com/security/cve/CVE-2015-7852, https://www.suse.com/security/cve/CVE-2015-7853, https://www.suse.com/security/cve/CVE-2015-7854, https://www.suse.com/security/cve/CVE-2015-7855, https://www.suse.com/security/cve/CVE-2015-7871
Affected packages
Package
Name: ntp
Purl: pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
