ntp-4.2.6p5-5.2.0.1.AXS4
エラータID: AXSA:2015-521:05
リリース日:
2015/10/28 Wednesday - 17:35
題名:
ntp-4.2.6p5-5.2.0.1.AXS4
影響のあるチャネル:
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- 現時点では CVE-2015-5300, CVE-2015-7704 の情報が公開されておりません。
CVE の情報が公開され次第情報をアップデートいたします。
一部CVEの翻訳文はJVNからの引用になります。
http://jvndb.jvn.jp/
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2015-5300
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to an unspecified number of requests from trusted sources, and leveraging a resulting denial of service (abort and restart).
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to an unspecified number of requests from trusted sources, and leveraging a resulting denial of service (abort and restart).
CVE-2015-7704
The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.
The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.
追加情報:
N/A
ダウンロード:
SRPMS
- ntp-4.2.6p5-5.2.0.1.AXS4.src.rpm
MD5: 9a11f2632151ce517c3449db18a89483
SHA-256: 7d2f43b3d3a890749430faa4be1ab96b4b63e5d3a683bdec6b89bcc91a556543
Size: 4.10 MB
Asianux Server 4 for x86
- ntp-4.2.6p5-5.2.0.1.AXS4.i686.rpm
MD5: ef6b2ca5afa32b39e96ff9ae1090c7f2
SHA-256: 70b9069be279129de74ac8ebdfc4a3e8fb38158b958cd245b1f28f6585112cdc
Size: 589.03 kB - ntpdate-4.2.6p5-5.2.0.1.AXS4.i686.rpm
MD5: d437c883ca49377cfcb7029b9ce923ad
SHA-256: 95fa5cf2e325130681fb53071c664f6256d77d1963d510f81c8d8afac940222a
Size: 75.76 kB
Asianux Server 4 for x86_64
- ntp-4.2.6p5-5.2.0.1.AXS4.x86_64.rpm
MD5: 9a7b7366ccfc8df7d4b4d5f736ab8163
SHA-256: 07c81c4900342dcd3b5b152d20c8b3391f2213a94a60af53586d2d645de25a51
Size: 594.56 kB - ntpdate-4.2.6p5-5.2.0.1.AXS4.x86_64.rpm
MD5: 0dd290bd3fcce9f3d053910d49c77269
SHA-256: 6ad7836a25bfec8f517281107616a5053732a085365ba518e4f0502f93536f01
Size: 75.85 kB