Oval Definition:oval:com.redhat.rhsa:def:20091039
Revision Date:2009-05-18Version:635
Title:RHSA-2009:1039: ntp security update (Important)
Description:The Network Time Protocol (NTP) is used to synchronize a computer's time with a referenced time source.

  • A buffer overflow flaw was discovered in the ntpd daemon's NTPv4 authentication code. If ntpd was configured to use public key cryptography for NTP packet authentication, a remote attacker could use this flaw to send a specially-crafted request packet that could crash ntpd. (CVE-2009-1252)

    Note: NTP authentication is not enabled by default.

  • A buffer overflow flaw was found in the ntpq diagnostic command. A malicious, remote server could send a specially-crafted reply to an ntpq request that could crash ntpq. (CVE-2009-0159)

    All ntp users are advised to upgrade to this updated package, which contains backported patches to resolve these issues. After installing the update, the ntpd daemon will be restarted automatically.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-0159
    CVE-2009-1252
    RHSA-2009:1039
    RHSA-2009:1039-01
    RHSA-2009:1039-01
    Platform(s):Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND ntp is earlier than 0:4.2.2p1-9.el5_3.2
  • AND ntp is signed with Red Hat redhatrelease2 key
  • BACK