ELSA-2014-2025

ELSA-2014-2025 - ntp security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2014-12-20

Description


[4.2.2p1-18.el5]
- don't generate weak control key for resolver (CVE-2014-9293)
- don't generate weak MD5 keys in ntp-keygen (CVE-2014-9294)
- fix buffer overflows via specially-crafted packets (CVE-2014-9295)


Related CVEs


CVE-2014-9293
CVE-2014-9295
CVE-2014-9294

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 5 (i386) ntp-4.2.2p1-18.el5_11.src.rpm97c42f7d321d318971d45a70af8e257fdd78bd883bd56c36cfac7f327e6cd687-ol5_i386_latest
ntp-4.2.2p1-18.el5_11.src.rpm97c42f7d321d318971d45a70af8e257fdd78bd883bd56c36cfac7f327e6cd687-ol5_u11_i386_patch
ntp-4.2.2p1-18.el5_11.i386.rpm7a122581bd091a8d53a49971b17ee6d40f14aa44ee7d3b5f68055de0d101dcbb-ol5_i386_latest
ntp-4.2.2p1-18.el5_11.i386.rpm7a122581bd091a8d53a49971b17ee6d40f14aa44ee7d3b5f68055de0d101dcbb-ol5_u11_i386_patch
Oracle Linux 5 (ia64) ntp-4.2.2p1-18.el5_11.src.rpm97c42f7d321d318971d45a70af8e257fdd78bd883bd56c36cfac7f327e6cd687-ol5_ia64_latest
ntp-4.2.2p1-18.el5_11.src.rpm97c42f7d321d318971d45a70af8e257fdd78bd883bd56c36cfac7f327e6cd687-ol5_u11_ia64_patch
ntp-4.2.2p1-18.el5_11.ia64.rpmb5a09f7d54f33e389d3de9132ac69904325a7b6093fa434247b0b373fc5cc8df-ol5_ia64_latest
ntp-4.2.2p1-18.el5_11.ia64.rpmb5a09f7d54f33e389d3de9132ac69904325a7b6093fa434247b0b373fc5cc8df-ol5_u11_ia64_patch
Oracle Linux 5 (x86_64) ntp-4.2.2p1-18.el5_11.src.rpm97c42f7d321d318971d45a70af8e257fdd78bd883bd56c36cfac7f327e6cd687-ol5_u11_x86_64_patch
ntp-4.2.2p1-18.el5_11.src.rpm97c42f7d321d318971d45a70af8e257fdd78bd883bd56c36cfac7f327e6cd687-ol5_x86_64_latest
ntp-4.2.2p1-18.el5_11.x86_64.rpm2cf6e2d1c7d645f7e73a551d23ea5efb80ce9b88e109bcbe8075402a91eb1421-exadata_dbserver_12.1.1.1.2_x86_64_base
ntp-4.2.2p1-18.el5_11.x86_64.rpm2cf6e2d1c7d645f7e73a551d23ea5efb80ce9b88e109bcbe8075402a91eb1421-ol5_u11_x86_64_patch
ntp-4.2.2p1-18.el5_11.x86_64.rpm2cf6e2d1c7d645f7e73a551d23ea5efb80ce9b88e109bcbe8075402a91eb1421-ol5_x86_64_latest



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete