Mandriva Linux Security Advisory : ntp (MDVSA-2015:046)

This script is Copyright (C) 2015 Tenable Network Security, Inc.


Synopsis :

The remote Mandriva Linux host is missing one or more security
updates.

Description :

Updated ntp packages fix security vulnerabilities :

Stephen Roettger of the Google Security Team, Sebastian Krahmer of the
SUSE Security Team and Harlan Stenn of Network Time Foundation
discovered that the length value in extension fields is not properly
validated in several code paths in ntp_crypto.c, which could lead to
information leakage or denial of service (CVE-2014-9297).

Stephen Roettger of the Google Security Team reported that ACLs based
on IPv6 ::1 (localhost) addresses can be bypassed (CVE-2014-9298).

See also :

http://advisories.mageia.org/MGASA-2015-0063.html

Solution :

Update the affected ntp, ntp-client and / or ntp-doc packages.

Risk factor :

High

Family: Mandriva Local Security Checks

Nessus Plugin ID: 81335 ()

Bugtraq ID:

CVE ID: CVE-2014-9297
CVE-2014-9298

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now