shield
Security update for ntp
slessp4-ntp-13534
This update for ntp fixes the following issues: Security issues fixed: - CVE-2016-1549: Significant additional protections against CVE-2016-1549 that was fixed in ntp-4.2.8p7 (bsc#1082210). - CVE-2018-7170: Ephemeral association time spoofing additional protection (bsc#1083424). - CVE-2018-7182: Buffer read overrun leads information leak in ctl_getitem() (bsc#1083426). - CVE-2018-7183: decodearr() can write beyond its buffer limit (bsc#1083417). - CVE-2018-7184: Interleaved symmetric mode cannot recover from bad state (bsc#1083422). - CVE-2018-7185: Unauthenticated packet can reset authenticated interleaved association (bsc#1083420). Bug fixes: - bsc#1077445: Don't use libevent's cached time stamps in sntp. - Disable CMAC in ntp when building against a version of OpenSSL that doesn't support it.
-
Release DateMar 26 2018
-
ReferencesBugzilla: 1082210, 1077445, 1083424, 1083426, 1083417, 1083422, 1083420
CVEs: CVE-2016-1549, CVE-2018-7170, CVE-2018-7182, CVE-2018-7183, CVE-2018-7184, CVE-2018-7185 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Linux Enterprise Server 11.4 ia64
-
Packages
SUSE Linux Enterprise Server for SAP Applications 11.4 ppc64
-
Packages
SUSE Linux Enterprise Server 11.4 s390x
-
Packages
SUSE Linux Enterprise Server 11.4 i586
-
Packages
SUSE Linux Enterprise Server for SAP All-in-One 11.4 x86_64
-
Packages