Oracle alert ELSA-2018-0855 (ntp)
| From: | Errata Announcements for Oracle Linux <el-errata@oss.oracle.com> | |
| To: | el-errata@oss.oracle.com | |
| Subject: | [El-errata] ELSA-2018-0855 Moderate: Oracle Linux 7 ntp security, bug fix, and enhancement update | |
| Date: | Tue, 17 Apr 2018 10:56:55 -0700 | |
| Message-ID: | <f3c63671-3234-31f9-8770-71067df0e0e8@oracle.com> |
Oracle Linux Security Advisory ELSA-2018-0855 http://linux.oracle.com/errata/ELSA-2018-0855.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: ntp-4.2.6p5-28.el7.x86_64.rpm ntp-doc-4.2.6p5-28.el7.noarch.rpm ntp-perl-4.2.6p5-28.el7.noarch.rpm ntpdate-4.2.6p5-28.el7.x86_64.rpm sntp-4.2.6p5-28.el7.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates/ntp-4.2.6p5-28.el... Description of changes: [4.2.6p5-28] - fix buffer overflow in datum refclock driver (CVE-2017-6462) - fix crash with invalid unpeer command (CVE-2017-6463) - fix potential crash with invalid server command (CVE-2017-6464) - add Spectracom TSYNC driver (#1491797) - fix initialization of system clock status (#1493452) - fix typos in ntpd man page (#1420453) - use SHA1 request key by default (#1442083) - use network-online target in ntpdate and sntp services (#1466947) [4.2.6p5-27] - fix CVE-2016-7429 patch to work correctly on multicast client (#1422944) [4.2.6p5-26] - don't limit rate of packets from sources (CVE-2016-7426) - don't change interface from received packets (CVE-2016-7429) - fix calculation of root distance again (CVE-2016-7433) - require authentication for trap commands (CVE-2016-9310) - fix crash when reporting peer event to trappers (CVE-2016-9311) _______________________________________________ El-errata mailing list El-errata@oss.oracle.com https://oss.oracle.com/mailman/listinfo/el-errata
