AIX 7.1 TL 3 : ntp (IV68430)

High Nessus Plugin ID 81275

Synopsis

The remote AIX host is missing a security patch.

Description

The version of NTP installed on the remote AIX host is affected by the following vulnerabilities :

- A security weakness exists due to the config_auth() function improperly generating default keys when no authentication key is defined in the ntp.conf file.
Key size is limited to 31 bits and the insecure ntp_random() function is used, resulting in cryptographically-weak keys with insufficient entropy. A remote attacker can exploit this to defeat cryptographic protection mechanisms via a brute-force attack.
(CVE-2014-9293)

- A security weakness exists due the use of a weak seed to prepare a random number generator used to generate symmetric keys. This allows a remote attacker to defeat cryptographic protection mechanisms via a brute-force attack. (CVE-2014-9294)

- Multiple stack-based buffer overflow conditions exist due to improper validation of user-supplied input when handling packets in the crypto_recv(), ctl_putdata(), and configure() functions when using autokey authentication. A remote attacker can exploit this, via a specially crafted packet, to cause a denial of service condition or the execution of arbitrary code.
(CVE-2014-9295)

Solution

Install the appropriate interim fix according to the vendor advisory.

See Also

http://aix.software.ibm.com/aix/efixes/security/ntp_advisory2.asc

Plugin Details

Severity: High

ID: 81275

File Name: aix_IV68430.nasl

Version: $Revision: 1.6 $

Type: local

Published: 2015/02/11

Modified: 2017/01/19

Dependencies: 12634

Risk Information

Risk Factor: High

CVSSv2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSSv3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/o:ibm:aix:7.1

Required KB Items: Host/AIX/lslpp, Host/local_checks_enabled, Host/AIX/version

Patch Publication Date: 2015/02/10

Vulnerability Publication Date: 2014/12/19

Reference Information

CVE: CVE-2014-9293, CVE-2014-9294, CVE-2014-9295

BID: 71757, 71761, 71762

OSVDB: 116066, 116067, 116068, 116069, 116074

CERT: 852879