MGASA-2015-0348

Source
https://advisories.mageia.org/MGASA-2015-0348.html
Import Source
https://advisories.mageia.org/MGASA-2015-0348.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2015-0348
Related
Published
2015-09-08T17:55:59Z
Modified
2015-09-08T17:18:17Z
Summary
Updated ntp packages fix security vulnerabilities
Details

Updated ntp packages fix security vulnerability:

A flaw was found in the way ntpd processed certain remote configuration packets. An attacker could use a specially crafted package to cause ntpd to crash if the attacker had authenticated access to remote ntpd configuration (CVE-2015-5146).

It was found that ntpd could crash due to an uninitialized variable when processing malformed logconfig configuration commands, for example, ntpq -c ":config logconfig a" (CVE-2015-5194).

It was found that ntpd exits with a segmentation fault when a statistics type that was not enabled during compilation (e.g. timingstats) is referenced by the statistics or filegen configuration command, for example, ntpq -c ':config statistics timingstats' ntpq -c ':config filegen timingstats' (CVE-2015-5195).

It was found that the :config command can be used to set the pidfile and driftfile paths without any restrictions. A remote attacker could use this flaw to overwrite a file on the file system with a file containing the pid of the ntpd process (immediately) or the current estimated drift of the system clock (in hourly intervals). For example, ntpq -c ':config pidfile /tmp/ntp.pid' ntpq -c ':config driftfile /tmp/ntp.drift' (CVE-2015-5196).

It was discovered that sntp would hang in an infinite loop when a crafted NTP packet was received, related to the conversion of the precision value in the packet to double (CVE-2015-5219).

References
Credits

Affected packages

Mageia:5 / ntp

Package

Name
ntp
Purl
pkg:rpm/mageia/ntp?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.2.6p5-24.1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / ntp

Package

Name
ntp
Purl
pkg:rpm/mageia/ntp?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.2.6p5-15.6.mga4

Ecosystem specific

{
    "section": "core"
}