ELSA-2014-2025

ELSA-2014-2025 - ntp security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2014-12-20

Description


[4.2.2p1-18.el5]
- don't generate weak control key for resolver (CVE-2014-9293)
- don't generate weak MD5 keys in ntp-keygen (CVE-2014-9294)
- fix buffer overflows via specially-crafted packets (CVE-2014-9295)


Related CVEs


CVE-2014-9293
CVE-2014-9294
CVE-2014-9295

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 5 (i386) ntp-4.2.2p1-18.el5_11.src.rpme0ecb6037365f66a741afaa0085ca6bf-
ntp-4.2.2p1-18.el5_11.i386.rpmee9c921630033c391afa4778910e4f68-
Oracle Linux 5 (ia64) ntp-4.2.2p1-18.el5_11.src.rpme0ecb6037365f66a741afaa0085ca6bf-
ntp-4.2.2p1-18.el5_11.ia64.rpm7cc275df6cb6b5fe81bb65486704a90e-
Oracle Linux 5 (x86_64) ntp-4.2.2p1-18.el5_11.src.rpme0ecb6037365f66a741afaa0085ca6bf-
ntp-4.2.2p1-18.el5_11.x86_64.rpm6b13511df6aa7c74abc48b906e04d8b6-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete