Oval Definition:oval:org.opensuse.security:def:78072
Revision Date:2014-12-19Version:1
Title:Security update for ntp (Critical)
Description:



The network timeservice ntp was updated to fix critical security issues (bnc#910764, CERT VU#852879)

* A potential remote code execution problem was found inside ntpd. The functions crypto_recv() (when using autokey authentication), ctl_putdata(), and configure() where updated to avoid buffer overflows that could be exploited. (CVE-2014-9295) * Furthermore a problem inside the ntpd error handling was found that is missing a return statement. This could also lead to a potentially attack vector. (CVE-2014-9296)
Family:unixClass:patch
Status:Reference(s):910764
CVE-2014-9295
CVE-2014-9296
Platform(s):SUSE Linux Enterprise Desktop 12
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 is installed
  • AND Package Information
  • ntp-4.2.6p5-31.1 is installed
  • OR ntp-doc-4.2.6p5-31.1 is installed
  • BACK