MGASA-2014-0541

Source
https://advisories.mageia.org/MGASA-2014-0541.html
Import Source
https://advisories.mageia.org/MGASA-2014-0541.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0541
Related
Published
2014-12-20T13:51:12Z
Modified
2014-12-20T13:44:41Z
Summary
Updated ntp packages fix security vulnerabilities
Details

Updated ntp packages fix security vulnerabilities:

If no authentication key is defined in the ntp.conf file, a cryptographically-weak default key is generated (CVE-2014-9293).

ntp-keygen before 4.2.7p230 uses a non-cryptographic random number generator with a weak seed to generate symmetric keys (CVE-2014-9294).

A remote unauthenticated attacker may craft special packets that trigger buffer overflows in the ntpd functions cryptorecv() (when using autokey authentication), ctlputdata(), and configure(). The resulting buffer overflows may be exploited to allow arbitrary malicious code to be executed with the privilege of the ntpd process (CVE-2014-9295).

A section of code in ntpd handling a rare error is missing a return statement, therefore processing did not stop when the error was encountered. This situation may be exploitable by an attacker (CVE-2014-9296).

The ntp package has been patched to fix these issues.

References
Credits

Affected packages

Mageia:4 / ntp

Package

Name
ntp
Purl
pkg:rpm/mageia/ntp?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.2.6p5-15.2.mga4

Ecosystem specific

{
    "section": "core"
}