MGASA-2014-0541

Source
https://advisories.mageia.org/MGASA-2014-0541.html
Import Source
https://advisories.mageia.org/MGASA-2014-0541.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0541
Upstream
Published
2014-12-20T13:51:12Z
Modified
2026-04-16T06:23:06Z
Summary
Updated ntp packages fix security vulnerabilities
Details

Updated ntp packages fix security vulnerabilities:

If no authentication key is defined in the ntp.conf file, a cryptographically-weak default key is generated (CVE-2014-9293).

ntp-keygen before 4.2.7p230 uses a non-cryptographic random number generator with a weak seed to generate symmetric keys (CVE-2014-9294).

A remote unauthenticated attacker may craft special packets that trigger buffer overflows in the ntpd functions crypto_recv() (when using autokey authentication), ctl_putdata(), and configure(). The resulting buffer overflows may be exploited to allow arbitrary malicious code to be executed with the privilege of the ntpd process (CVE-2014-9295).

A section of code in ntpd handling a rare error is missing a return statement, therefore processing did not stop when the error was encountered. This situation may be exploitable by an attacker (CVE-2014-9296).

The ntp package has been patched to fix these issues.

References
Credits

Affected packages

Mageia:4 / ntp

Package

Name
ntp
Purl
pkg:rpm/mageia/ntp?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.2.6p5-15.2.mga4

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2014-0541.json"