VYPR

rpm package

suse/ntp&distro=SUSE Linux Enterprise Server 12 SP1

pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1

Vulnerabilities (45)

  • CVE-2016-4956MedJul 5, 2016
    affected < 4.2.8p8-14.1fixed 4.2.8p8-14.1

    ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-1548.

  • CVE-2016-4955MedJul 5, 2016
    affected < 4.2.8p8-14.1fixed 4.2.8p8-14.1

    ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet with an incorrect MAC value at a certain time.

  • CVE-2016-4954HigJul 5, 2016
    affected < 4.2.8p8-14.1fixed 4.2.8p8-14.1

    The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstrated by triggering an incorrec

  • CVE-2016-4953HigJul 5, 2016
    affected < 4.2.8p8-14.1fixed 4.2.8p8-14.1

    ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.

  • CVE-2015-7974HigJan 26, 2016
    affected < 4.2.8p6-8.2fixed 4.2.8p6-8.2

    NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."

Page 3 of 3