|
|
Log in / Subscribe / Register

Mageia alert MGASA-2015-0348 (ntp)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2015-0348: Updated ntp packages fix security vulnerabilities
Date:  Tue, 8 Sep 2015 19:56:39 +0200
Message-ID:  <20150908175639.3006048CD1@valstar.mageia.org>

MGASA-2015-0348 - Updated ntp packages fix security vulnerabilities Publication date: 08 Sep 2015 URL: http://advisories.mageia.org/MGASA-2015-0348.html Type: security Affected Mageia releases: 4, 5 CVE: CVE-2015-5146, CVE-2015-5194, CVE-2015-5195, CVE-2015-5196, CVE-2015-5219 Description: Updated ntp packages fix security vulnerability: A flaw was found in the way ntpd processed certain remote configuration packets. An attacker could use a specially crafted package to cause ntpd to crash if the attacker had authenticated access to remote ntpd configuration (CVE-2015-5146). It was found that ntpd could crash due to an uninitialized variable when processing malformed logconfig configuration commands, for example, ntpq -c ":config logconfig a" (CVE-2015-5194). It was found that ntpd exits with a segmentation fault when a statistics type that was not enabled during compilation (e.g. timingstats) is referenced by the statistics or filegen configuration command, for example, ntpq -c ':config statistics timingstats' ntpq -c ':config filegen timingstats' (CVE-2015-5195). It was found that the :config command can be used to set the pidfile and driftfile paths without any restrictions. A remote attacker could use this flaw to overwrite a file on the file system with a file containing the pid of the ntpd process (immediately) or the current estimated drift of the system clock (in hourly intervals). For example, ntpq -c ':config pidfile /tmp/ntp.pid' ntpq -c ':config driftfile /tmp/ntp.drift' (CVE-2015-5196). It was discovered that sntp would hang in an infinite loop when a crafted NTP packet was received, related to the conversion of the precision value in the packet to double (CVE-2015-5219). References: - https://bugs.mageia.org/show_bug.cgi?id=16322 - http://support.ntp.org/bin/view/Main/SecurityNotice#June_... - http://openwall.com/lists/oss-security/2015/08/25/3 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5146 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5194 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5195 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5196 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5219 SRPMS: - 4/core/ntp-4.2.6p5-15.6.mga4 - 5/core/ntp-4.2.6p5-24.1.mga5


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds