Oval Definition:oval:org.mitre.oval:def:22471
Revision Date:2014-05-26Version:13
Title:ELSA-2009:0046: ntp security update (Moderate)
Description:NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2009-0021
ELSA-2009:0046-01
Platform(s):Oracle Linux 5
Product(s):ntp
Definition Synopsis
  • Oracle Linux 5.x
  • AND ntp is earlier than 0:4.2.2p1-9.el5_3.1
  • BACK