Oval Definition:
oval:org.mitre.oval:def:28798
Revision Date
:
2015-07-13
Version
:
19
Title
:
Network Time Protocol (NTP) vulnerability in AIX
Description
:
util/ntp-keygen.c in ntp-keygen in NTP before 4.2.7p230 uses a weak RNG seed, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
Family
:
unix
Class
:
vulnerability
Status
:
ACCEPTED
Reference(s)
:
CVE-2014-9294
Platform(s)
:
IBM AIX 6.1
IBM AIX 7.1
Product(s)
:
Definition Synopsis
platforms
IBM AIX 6.1 is installed
OR
IBM AIX 7.1 is installed
AND
filesets
File Version Exists
bos.net.tcp.client greater than or equal 5.3.12.0
AND
bos.net.tcp.client less than or equal 5.3.12.10
OR
File Version Exists
bos.net.tcp.client greater than or equal 6.1.8.0
AND
bos.net.tcp.client less than or equal 7.1.2.19
OR
File Version Exists
bos.net.tcp.client greater than or equal 6.1.9.0
AND
bos.net.tcp.client less than or equal 6.1.9.30
OR
File Version Exists
bos.net.tcp.client greater than or equal 7.1.2.0
AND
bos.net.tcp.client less than or equal 7.1.2.19
OR
File Version Exists
bos.net.tcp.client greater than or equal 7.1.3.0
AND
bos.net.tcp.client less than or equal 7.1.3.30
BACK