ntp-4.2.6p5-25.0.1.el7.AXS7

エラータID: AXSA:2016-1181:02

Release date: 
Tuesday, December 13, 2016 - 11:24
Subject: 
ntp-4.2.6p5-25.0.1.el7.AXS7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
Moderate
Description: 

The Network Time Protocol (NTP) is used to synchronize a computer's
time with another reference time source. This package includes ntpd
(a daemon which continuously adjusts system time) and utilities used
to query and configure the ntpd daemon.

Perl scripts ntp-wait and ntptrace are in the ntp-perl package,
ntpdate is in the ntpdate package and sntp is in the sntp package.
The documentation is in the ntp-doc package.

Security issues fixed with this release:

CVE-2015-5194
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2015-5195
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2015-5196
** REJECT **

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-7703. Reason:
This candidate is a reservation duplicate of CVE-2015-7703. Notes:
All CVE users should reference CVE-2015-7703 instead of this
candidate. All references and descriptions in this candidate have
been removed to prevent accidental usage.
CVE-2015-5219
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2015-7691
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2015-7692
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2015-7701
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2015-7702
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2015-7703
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2015-7852
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2015-7974
NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer
associations of symmetric keys when authenticating packets, which
might allow remote attackers to conduct impersonation attacks via an
arbitrary trusted key, aka a "skeleton key."
CVE-2015-7977
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2015-7978
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2015-7979
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2015-8158
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.

Additional Changes:

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. ntp-4.2.6p5-25.0.1.el7.AXS7.src.rpm
    MD5: 22aec0fc36c4d5f3c7d3a07f993c4f58
    SHA-256: 6b864ac4a2a95f54ad8a93a277ef95a71326453b49bd987e1079a4b36edc82d7
    Size: 4.12 MB

Asianux Server 7 for x86_64
  1. ntp-4.2.6p5-25.0.1.el7.AXS7.x86_64.rpm
    MD5: 9f569071ac1ef830c013cd34c11536d8
    SHA-256: 4276b7b91b425c789edee92d81895dabc0f992a97dc520c71f159785a9bb971a
    Size: 545.86 kB
  2. ntpdate-4.2.6p5-25.0.1.el7.AXS7.x86_64.rpm
    MD5: fb4c30173e4d81f97bbedc862e48bb90
    SHA-256: 5d71d8afba2395a86461d7947c26ec5cb4b6f9dbb204c05aceed42362443ff23
    Size: 84.23 kB