Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2018-0855

Опубликовано: 16 апр. 2018
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2018-0855: ntp security, bug fix, and enhancement update (MODERATE)

[4.2.6p5-28.0.1]

  • Bump release to avoid ULN conflict with Oracle modified errata.

[4.2.6p5-28]

  • fix buffer overflow in datum refclock driver (CVE-2017-6462)
  • fix crash with invalid unpeer command (CVE-2017-6463)
  • fix potential crash with invalid server command (CVE-2017-6464)
  • add Spectracom TSYNC driver (#1491797)
  • fix initialization of system clock status (#1493452)
  • fix typos in ntpd man page (#1420453)
  • use SHA1 request key by default (#1442083)
  • use network-online target in ntpdate and sntp services (#1466947)

[4.2.6p5-27]

  • fix CVE-2016-7429 patch to work correctly on multicast client (#1422944)

[4.2.6p5-26]

  • don't limit rate of packets from sources (CVE-2016-7426)
  • don't change interface from received packets (CVE-2016-7429)
  • fix calculation of root distance again (CVE-2016-7433)
  • require authentication for trap commands (CVE-2016-9310)
  • fix crash when reporting peer event to trappers (CVE-2016-9311)

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

ntp

4.2.6p5-28.0.1.el7

ntp-doc

4.2.6p5-28.0.1.el7

ntp-perl

4.2.6p5-28.0.1.el7

ntpdate

4.2.6p5-28.0.1.el7

sntp

4.2.6p5-28.0.1.el7

Oracle Linux x86_64

ntp

4.2.6p5-28.0.1.el7

ntp-doc

4.2.6p5-28.0.1.el7

ntp-perl

4.2.6p5-28.0.1.el7

ntpdate

4.2.6p5-28.0.1.el7

sntp

4.2.6p5-28.0.1.el7

Связанные уязвимости

oracle-oval
около 8 лет назад

ELSA-2017-3071: ntp security update (MODERATE)

suse-cvrf
больше 8 лет назад

Security update for ntp

suse-cvrf
больше 8 лет назад

Security update for ntp

suse-cvrf
больше 8 лет назад

Security update for ntp

CVSS3: 7.8
ubuntu
больше 8 лет назад

Buffer overflow in the legacy Datum Programmable Time Server (DPTS) refclock driver in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via a crafted /dev/datum device.