Описание
Recommended update for ntp
This collective update for the Network Time Protocol daemon (ntp) provides fixes for the following reports:
Список пакетов
SUSE Linux Enterprise Server 11 SP2
SUSE Linux Enterprise Server 11 SP2-LTSS
SUSE Linux Enterprise Server for SAP Applications 11 SP2
Ссылки
- Link for SUSE-SU-2015:0259-2
- E-Mail link for SUSE-SU-2015:0259-2
- SUSE Security Ratings
- SUSE Bug 758253
- SUSE Bug 771480
- SUSE Bug 910764
- SUSE Bug 911792
- SUSE CVE CVE-2014-9293 page
- SUSE CVE CVE-2014-9294 page
- SUSE CVE CVE-2014-9295 page
- SUSE CVE CVE-2014-9297 page
- SUSE CVE CVE-2014-9298 page
Описание
The config_auth function in ntpd in NTP before 4.2.7p11, when an auth key is not configured, improperly generates a key, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
Затронутые продукты
Ссылки
- CVE-2014-9293
- SUSE Bug 910764
- SUSE Bug 911053
- SUSE Bug 911792
- SUSE Bug 959243
Описание
util/ntp-keygen.c in ntp-keygen in NTP before 4.2.7p230 uses a weak RNG seed, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
Затронутые продукты
Ссылки
- CVE-2014-9294
- SUSE Bug 910764
- SUSE Bug 911053
- SUSE Bug 911792
- SUSE Bug 959243
Описание
Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet, related to (1) the crypto_recv function when the Autokey Authentication feature is used, (2) the ctl_putdata function, and (3) the configure function.
Затронутые продукты
Ссылки
- CVE-2014-9295
- SUSE Bug 910764
- SUSE Bug 911053
- SUSE Bug 911792
- SUSE Bug 916239
- SUSE Bug 959243
Описание
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-9750, CVE-2014-9751. Reason: this ID was intended for one issue, but was associated with two issues. Notes: All CVE users should consult CVE-2014-9750 and CVE-2014-9751 to identify the ID or IDs of interest. All references and descriptions in this candidate have been removed to prevent accidental usage.
Затронутые продукты
Ссылки
- CVE-2014-9297
- SUSE Bug 911792
- SUSE Bug 948963
- SUSE Bug 959243
Описание
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-9750, CVE-2014-9751. Reason: this ID was intended for one issue, but was associated with two issues. Notes: All CVE users should consult CVE-2014-9750 and CVE-2014-9751 to identify the ID or IDs of interest. All references and descriptions in this candidate have been removed to prevent accidental usage.
Затронутые продукты
Ссылки
- CVE-2014-9298
- SUSE Bug 911792
- SUSE Bug 948963
- SUSE Bug 959243