Chapter 1. Package Updates
182
1.158. ntp
1.158.1. RHSA-2009:1039: Important security update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2009:1039
1286
An updated ntp package that fixes two security issues is now available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red Hat Security Response
Team.
The Network Time Protocol (NTP) is used to synchronize a computer's time with a referenced time
source.
A buffer overflow flaw was discovered in the ntpd daemon's NTPv4 authentication code. If ntpd was
configured to use public key cryptography for NTP packet authentication, a remote attacker could use
this flaw to send a specially-crafted request packet that could crash ntpd. (
CVE-2009-1252
1287
)
Note
NTP authentication is not enabled by default.
A buffer overflow flaw was found in the ntpq diagnostic command. A malicious, remote server could
send a specially-crafted reply to an ntpq request that could crash ntpq. (
CVE-2009-0159
1288
)
All ntp users are advised to upgrade to this updated package, which contains backported patches to
resolve these issues. After installing the update, the ntpd daemon will be restarted automatically.
1.158.2. RHSA-2009:0046: Moderate security update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2009:0046
1289
Updated ntp packages to correct a security issue are now available for Red Hat Enterprise Linux 4 and
5.
This update has been rated as having moderate security impact by the Red Hat Security Response
Team.
The Network Time Protocol (NTP) is used to synchronize a computer's time with a referenced time
source.
1287
https://www.redhat.com/security/data/cve/CVE-2009-1252.html
1288
https://www.redhat.com/security/data/cve/CVE-2009-0159.html
Summary of Contents for ENTERPRISE 5.4 RELEASE NOTES
Page 1: ...Red Hat Enterprise Linux 5 4 Technical Notes Every Change to Every Package ...
Page 18: ...xviii ...
Page 306: ...288 ...
Page 464: ...446 ...
Page 466: ...448 ...