SUSE-SU-2016:1471-1

Source
https://www.suse.com/support/update/announcement/2016/suse-su-20161471-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2016:1471-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2016:1471-1
Related
Published
2016-06-01T12:36:52Z
Modified
2016-06-01T12:36:52Z
Summary
Security update for ntp
Details

This update for ntp fixes the following issues:

  • Separate the creation of ntp.keys and key #1 in it to avoid problems when upgrading installations that have the file, but no key #1, which is needed e.g. by 'rcntp addserver'.

  • Update to 4.2.8p7 (bsc#977446):

    • CVE-2016-1547, bsc#977459: Validate crypto-NAKs, AKA: CRYPTO-NAK DoS.
    • CVE-2016-1548, bsc#977461: Interleave-pivot
    • CVE-2016-1549, bsc#977451: Sybil vulnerability: ephemeral association attack.
    • CVE-2016-1550, bsc#977464: Improve NTP security against buffer comparison timing attacks.
    • CVE-2016-1551, bsc#977450: Refclock impersonation vulnerability
    • CVE-2016-2516, bsc#977452: Duplicate IPs on unconfig directives will cause an assertion botch in ntpd.
    • CVE-2016-2517, bsc#977455: remote configuration trustedkey/ requestkey/controlkey values are not properly validated.
    • CVE-2016-2518, bsc#977457: Crafted addpeer with hmode > 7 causes array wraparound with MATCH_ASSOC.
    • CVE-2016-2519, bsc#977458: ctl_getitem() return value not always checked.
    • integrate ntp-fork.patch
    • Improve the fixes for: CVE-2015-7704, CVE-2015-7705, CVE-2015-7974
  • Restrict the parser in the startup script to the first occurrance of 'keys' and 'controlkey' in ntp.conf (bsc#957226).
References

Affected packages

SUSE:OpenStack Cloud 5 / ntp

Package

Name
ntp
Purl
pkg:rpm/suse/ntp&distro=SUSE%20OpenStack%20Cloud%205

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.2.8p7-44.1

Ecosystem specific

{
    "binaries": [
        {
            "ntp-doc": "4.2.8p7-44.1",
            "ntp": "4.2.8p7-44.1"
        }
    ]
}

SUSE:Manager 2.1 / ntp

Package

Name
ntp
Purl
pkg:rpm/suse/ntp&distro=SUSE%20Manager%202.1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.2.8p7-44.1

Ecosystem specific

{
    "binaries": [
        {
            "ntp-doc": "4.2.8p7-44.1",
            "ntp": "4.2.8p7-44.1"
        }
    ]
}

SUSE:Manager Proxy 2.1 / ntp

Package

Name
ntp
Purl
pkg:rpm/suse/ntp&distro=SUSE%20Manager%20Proxy%202.1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.2.8p7-44.1

Ecosystem specific

{
    "binaries": [
        {
            "ntp-doc": "4.2.8p7-44.1",
            "ntp": "4.2.8p7-44.1"
        }
    ]
}

SUSE:Linux Enterprise Server 11 SP2-LTSS / ntp

Package

Name
ntp
Purl
pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP2-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.2.8p7-44.1

Ecosystem specific

{
    "binaries": [
        {
            "ntp-doc": "4.2.8p7-44.1",
            "ntp": "4.2.8p7-44.1"
        }
    ]
}

SUSE:Linux Enterprise Server 11 SP3-LTSS / ntp

Package

Name
ntp
Purl
pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.2.8p7-44.1

Ecosystem specific

{
    "binaries": [
        {
            "ntp-doc": "4.2.8p7-44.1",
            "ntp": "4.2.8p7-44.1"
        }
    ]
}

SUSE:Linux Enterprise Server 11 SP3-TERADATA / ntp

Package

Name
ntp
Purl
pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATA

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.2.8p7-44.1

Ecosystem specific

{
    "binaries": [
        {
            "ntp-doc": "4.2.8p7-44.1",
            "ntp": "4.2.8p7-44.1"
        }
    ]
}