SCIENTIFIC-LINUX-ERRATA Archives

October 2017

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Thu, 26 Oct 2017 13:54:12 -0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (35 lines)
Synopsis:          Moderate: ntp security update
Advisory ID:       SLSA-2017:3071-1
Issue Date:        2017-10-26
CVE Numbers:       CVE-2017-6464
                   CVE-2017-6462
                   CVE-2017-6463
--

Security Fix(es):

* Two vulnerabilities were discovered in the NTP server's parsing of
configuration directives. A remote, authenticated attacker could cause
ntpd to crash by sending a crafted message. (CVE-2017-6463, CVE-2017-6464)

* A vulnerability was found in NTP, in the parsing of packets from the
/dev/datum device. A malicious device could send crafted messages, causing
ntpd to crash. (CVE-2017-6462)
--

SL6
  x86_64
    ntp-4.2.6p5-12.el6_9.1.x86_64.rpm
    ntp-debuginfo-4.2.6p5-12.el6_9.1.x86_64.rpm
    ntpdate-4.2.6p5-12.el6_9.1.x86_64.rpm
    ntp-perl-4.2.6p5-12.el6_9.1.x86_64.rpm
  i386
    ntp-4.2.6p5-12.el6_9.1.i686.rpm
    ntp-debuginfo-4.2.6p5-12.el6_9.1.i686.rpm
    ntpdate-4.2.6p5-12.el6_9.1.i686.rpm
    ntp-perl-4.2.6p5-12.el6_9.1.i686.rpm
  noarch
    ntp-doc-4.2.6p5-12.el6_9.1.noarch.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2