ntp-4.2.6p5-29.2.0.1.el7.AXS7

エラータID: AXSA:2020-199:01

Release date: 
Thursday, July 2, 2020 - 05:07
Subject: 
ntp-4.2.6p5-29.2.0.1.el7.AXS7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
Moderate
Description: 

The Network Time Protocol (NTP) is used to synchronize a computer's time with another referenced time source. These packages include the ntpd service which continuously adjusts system time and utilities used to query and configure the ntpd service.

Security Fix(es):

* ntp: ntpd using highly predictable transmit timestamps could result in time change or DoS (CVE-2020-13817)

* ntp: DoS on client ntpd using server mode packet (CVE-2020-11868)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2020-11868
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.
CVE-2020-13817
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query time from the victim's ntpd instance.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. ntp-4.2.6p5-29.2.0.1.el7.AXS7.src.rpm
    MD5: 9143a605e46144dc587e395fcd5393c0
    SHA-256: c4458d7c82b036702dc2214f14bf0a9e7c809742f695adf80cfd3f5af4cbf32d
    Size: 4.14 MB

Asianux Server 7 for x86_64
  1. ntp-4.2.6p5-29.2.0.1.el7.AXS7.x86_64.rpm
    MD5: d57edc94baf9041fc26a6667d7f0c5a0
    SHA-256: a1b2cce3dfb932acbbd506442183e76090f3396087621621597f06ec0aabd56b
    Size: 547.75 kB
  2. ntpdate-4.2.6p5-29.2.0.1.el7.AXS7.x86_64.rpm
    MD5: 07fc0e13f6f97bb7b81e885443eb26b1
    SHA-256: d23ebf644b9526b0da70b26d32eeca3e46095dc8ed43a7bf435288ff842c8803
    Size: 85.76 kB