OracleVM 3.3 / 3.4 : ntp (OVMSA-2016-0082)

High Nessus Plugin ID 91419


The remote OracleVM host is missing one or more security updates.


The remote OracleVM system is missing necessary patches to address critical security updates :

- don't allow spoofed packets to demobilize associations (CVE-2015-7979, CVE-2016-1547)

- don't allow spoofed packet to enable symmetric interleaved mode (CVE-2016-1548)

- check mode of new source in config command (CVE-2016-2518)

- make MAC check resilient against timing attack (CVE-2016-1550)

- don't accept server/peer packets with zero origin timestamp (CVE-2015-8138)

- fix crash with reslist command (CVE-2015-7977, CVE-2015-7978)

- fix crash with invalid logconfig command (CVE-2015-5194)

- fix crash when referencing disabled statistic type (CVE-2015-5195)

- don't hang in sntp with crafted reply (CVE-2015-5219)

- don't crash with crafted autokey packet (CVE-2015-7691, CVE-2015-7692, CVE-2015-7702)

- fix memory leak with autokey (CVE-2015-7701)

- don't allow setting driftfile and pidfile remotely (CVE-2015-7703)

- don't crash in ntpq with crafted packet (CVE-2015-7852)

- add option to set Differentiated Services Code Point (DSCP) (#1228314)

- extend rawstats log (#1242895)

- fix resetting of leap status (#1243034)

- report clock state changes related to leap seconds (#1242937)

- allow -4/-6 on restrict lines with mask (#1232146)

- retry joining multicast groups (#1288534)

- explain synchronised state in ntpstat man page (#1286969)

- check origin timestamp before accepting KoD RATE packet (CVE-2015-7704)

- allow only one step larger than panic threshold with -g (CVE-2015-5300)


Update the affected ntp / ntpdate packages.

See Also

Plugin Details

Severity: High

ID: 91419

File Name: oraclevm_OVMSA-2016-0082.nasl

Version: $Revision: 2.9 $

Type: local

Published: 2016/06/01

Modified: 2017/08/17

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 7.8

Temporal Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:ND


Base Score: 7.5

Temporal Score: 6.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:X

Vulnerability Information

CPE: p-cpe:/a:oracle:vm:ntp, p-cpe:/a:oracle:vm:ntpdate, cpe:/o:oracle:vm_server:3.3, cpe:/o:oracle:vm_server:3.4

Required KB Items: Host/local_checks_enabled, Host/OracleVM/release, Host/OracleVM/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2016/05/31

Reference Information

CVE: CVE-2015-5194, CVE-2015-5195, CVE-2015-5219, CVE-2015-5300, CVE-2015-7691, CVE-2015-7692, CVE-2015-7701, CVE-2015-7702, CVE-2015-7703, CVE-2015-7704, CVE-2015-7852, CVE-2015-7977, CVE-2015-7978, CVE-2015-7979, CVE-2015-8138, CVE-2016-1547, CVE-2016-1548, CVE-2016-1550, CVE-2016-2518

OSVDB: 116071, 126663, 126664, 126665, 126666, 129302, 129307, 129308, 129309, 129311, 129315, 133378, 133383, 133384, 133391, 137711, 137712, 137714, 137734

TRA: TRA-2015-04