ELSA-2015-1459

ELSA-2015-1459 - ntp security, bug fix, and enhancement update

Type:SECURITY
Severity:MODERATE
Release Date:2015-07-28

Description


[4.2.6p5-5]
- reject packets without MAC when authentication is enabled (CVE-2015-1798)
- protect symmetric associations with symmetric key against DoS attack
(CVE-2015-1799)
- fix generation of MD5 keys with ntp-keygen on big-endian systems
(CVE-2015-3405)
- log when stepping clock for leap second or ignoring it with -x (#1204625)

[4.2.6p5-4]
- fix typos in ntpd man page (#1194463)


Related CVEs


CVE-2014-9297
CVE-2014-9298
CVE-2015-1798
CVE-2015-1799
CVE-2015-3405

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 6 (i386) ntp-4.2.6p5-5.el6.src.rpme0dbd42921d58b33c5aeb5be912ed59bELSA-2018-3854
ntp-4.2.6p5-5.el6.i686.rpm7b83ef8b08c40fcccc202399f0baa5c2ELSA-2018-3854
ntp-doc-4.2.6p5-5.el6.noarch.rpmdf7dc2c7dd7d54de8489b917feffe4c7ELSA-2018-3854
ntp-perl-4.2.6p5-5.el6.i686.rpm02f05f12738e8c0cb171b1dc52d235aaELSA-2018-3854
ntpdate-4.2.6p5-5.el6.i686.rpm54ca9bccb1b767fbe4d953fdfcdada89ELSA-2018-3854
Oracle Linux 6 (x86_64) ntp-4.2.6p5-5.el6.src.rpme0dbd42921d58b33c5aeb5be912ed59bELSA-2018-3854
ntp-4.2.6p5-5.el6.x86_64.rpmc32c6a99d57771e84f37e6c01c7f5a27ELSA-2018-3854
ntp-doc-4.2.6p5-5.el6.noarch.rpmdf7dc2c7dd7d54de8489b917feffe4c7ELSA-2018-3854
ntp-perl-4.2.6p5-5.el6.x86_64.rpm021a3646df8502694d8fb34aa1634ac5ELSA-2018-3854
ntpdate-4.2.6p5-5.el6.x86_64.rpm12f030a135bfc56c1fb83c68b196b585ELSA-2018-3854



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete