OVMSA-2014-0085

OVMSA-2014-0085 - ntp security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2014-12-23

Description


[4.2.6p5-2]
- don't generate weak control key for resolver (CVE-2014-9293)
- don't generate weak MD5 keys in ntp-keygen (CVE-2014-9294)
- fix buffer overflows via specially-crafted packets (CVE-2014-9295)
- don't mobilize passive association when authentication fails (CVE-2014-9296)


Related CVEs


CVE-2014-9293
CVE-2014-9294
CVE-2014-9295
CVE-2014-9296

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle VM 3.3 (x86_64) ntp-4.2.6p5-2.el6_6.src.rpmdd6a6e1458da216cfe5b393065982a4fOVMSA-2018-0290
ntp-4.2.6p5-2.el6_6.x86_64.rpm7c892b6a276bf59d396a0880ba5b5646OVMSA-2018-0290
ntpdate-4.2.6p5-2.el6_6.x86_64.rpma856123ca3bd10bfafaca279308980c5OVMSA-2018-0290



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete