|
|
Subscribe / Log in / New account

ntp: multiple code execution vulnerabilities

Package(s):ntp CVE #(s):CVE-2014-9293 CVE-2014-9294 CVE-2014-9295 CVE-2014-9296
Created:December 22, 2014 Updated:January 29, 2015
Description: From the CERT advisory:

Google Security Team researchers Neel Mehta and Stephen Roettger have coordinated multiple vulnerabilities with CERT/CC concerning the Network Time Protocol (NTP). As NTP is widely used within operational Industrial Control Systems deployments, NCCIC/ICS-CERT is providing this information for US Critical Infrastructure asset owners and operators for awareness and to identify mitigations for affected devices. ICS-CERT may release updates as additional information becomes available.

These vulnerabilities could be exploited remotely. Exploits that target these vulnerabilities are publicly available.

Products using NTP service prior to NTP-4.2.8 are affected. No specific vendor is specified because this is an open source protocol.

Alerts:
Mandriva MDVSA-2015:140 ntp 2015-03-29
SUSE SUSE-SU-2015:0322-1 xntp 2015-02-19
SUSE SUSE-SU-2015:0259-3 ntp 2015-02-16
SUSE SUSE-SU-2015:0259-2 ntp 2015-02-13
SUSE SUSE-SU-2015:0274-1 ntp 2015-02-12
SUSE SUSE-SU-2015:0259-1 ntp 2015-02-12
Red Hat RHSA-2015:0104-01 ntp 2015-01-28
Mandriva MDVSA-2015:003 ntp 2015-01-05
Fedora FEDORA-2014-17395 ntp 2014-12-31
Gentoo 201412-34 ntp 2014-12-24
SUSE SUSE-SU-2014:1686-2 xntp 2014-12-24
SUSE SUSE-SU-2014:1690-1 ntp 2014-12-23
Fedora FEDORA-2014-17367 ntp 2014-12-23
SUSE SUSE-SU-2014:1686-1 ntp 2014-12-22
Slackware SSA:2014-356-01 ntp 2014-12-22
Ubuntu USN-2449-1 ntp 2014-12-22
Scientific Linux SLSA-2014:2025-1 ntp 2014-12-20
Scientific Linux SLSA-2014:2024-1 ntp 2014-12-20
Oracle ELSA-2014-2025 ntp 2014-12-20
Oracle ELSA-2014-2024 ntp 2014-12-20
Oracle ELSA-2014-2024 ntp 2014-12-20
openSUSE openSUSE-SU-2014:1680-1 ntp 2014-12-22
openSUSE openSUSE-SU-2014:1670-1 ntp 2014-12-20
Mageia MGASA-2014-0541 ntp 2014-12-20
Fedora FEDORA-2014-17361 ntp 2014-12-22
Debian-LTS DLA-116-1 ntp 2014-12-20
Debian DSA-3108-1 ntp 2014-12-20
CentOS CESA-2014:2025 ntp 2014-12-20
CentOS CESA-2014:2024 ntp 2014-12-20
CentOS CESA-2014:2024 ntp 2014-12-20
Red Hat RHSA-2014:2025-01 ntp 2014-12-20
Red Hat RHSA-2014:2024-01 ntp 2014-12-20

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds