Synopsis:          Moderate: ntp security update
Advisory ID:       SLSA-2017:3071-1
Issue Date:        2017-10-26
CVE Numbers:       CVE-2017-6464
                   CVE-2017-6462
                   CVE-2017-6463
--

Security Fix(es):

* Two vulnerabilities were discovered in the NTP server's parsing of
configuration directives. A remote, authenticated attacker could cause
ntpd to crash by sending a crafted message. (CVE-2017-6463, CVE-2017-6464)

* A vulnerability was found in NTP, in the parsing of packets from the
/dev/datum device. A malicious device could send crafted messages, causing
ntpd to crash. (CVE-2017-6462)
--

SL6
  x86_64
    ntp-4.2.6p5-12.el6_9.1.x86_64.rpm
    ntp-debuginfo-4.2.6p5-12.el6_9.1.x86_64.rpm
    ntpdate-4.2.6p5-12.el6_9.1.x86_64.rpm
    ntp-perl-4.2.6p5-12.el6_9.1.x86_64.rpm
  i386
    ntp-4.2.6p5-12.el6_9.1.i686.rpm
    ntp-debuginfo-4.2.6p5-12.el6_9.1.i686.rpm
    ntpdate-4.2.6p5-12.el6_9.1.i686.rpm
    ntp-perl-4.2.6p5-12.el6_9.1.i686.rpm
  noarch
    ntp-doc-4.2.6p5-12.el6_9.1.noarch.rpm

- Scientific Linux Development Team