OracleVM 2.1 : ntp (OVMSA-2009-0011)

medium Nessus Plugin ID 79458
New! Plugin Severity Now Using CVSS v3

The calculated severity for Plugins has been updated to use CVSS v3 by default. Plugins that do not have a CVSS v3 score will fall back to CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Synopsis

The remote OracleVM host is missing a security update.

Description

The remote OracleVM system is missing necessary patches to address critical security updates :

CVE-2009-0159 Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitrary code via a crafted response.

CVE-2009-1252 Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.

CVE-2009-0021 NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

- fix buffer overflow when parsing Autokey association message (#500783, CVE-2009-1252)

- fix buffer overflow in ntpq (#500783, CVE-2009-0159)

- fix check for malformed signatures (#479698, CVE-2009-0021)

- fix selecting multicast interface (#444106)

- disable kernel discipline when -x option is used (#431729)

- avoid use of uninitialized floating-point values in clock_select (#250838)

- generate man pages from html source, include config man pages (#307271)

- add note about paths and exit codes to ntpd man page (#242925, #246568)

- add section about exit codes to ntpd man page (#319591)

- always return 0 in scriptlets

- pass additional options to ntpdate (#240141)

- fix broadcast client to accept broadcasts on 255.255.255.255 (#226958)

- compile with crypto support on 64bit architectures (#239580)

- add ncurses-devel to buildrequires (#239580)

- exit with nonzero code if ntpd -q did not set clock (#240134)

- fix return codes in init script (#240118)

Solution

Update the affected ntp package.

See Also

https://oss.oracle.com/pipermail/oraclevm-errata/2009-May/000024.html

Plugin Details

Severity: Medium

ID: 79458

File Name: oraclevm_OVMSA-2009-0011.nasl

Version: 1.10

Type: local

Published: 11/26/2014

Updated: 1/14/2021

Dependencies: ssh_get_info.nasl

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: E:U/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:oracle:vm:ntp, cpe:/o:oracle:vm_server:2.1

Required KB Items: Host/local_checks_enabled, Host/OracleVM/release, Host/OracleVM/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 5/27/2009

Vulnerability Publication Date: 1/7/2009

Reference Information

CVE: CVE-2008-5077, CVE-2009-0021, CVE-2009-0159, CVE-2009-1252

BID: 33150, 34481, 35017

CWE: 20, 119, 287