OracleVM 2.1 : ntp (OVMSA-2009-0011)

medium Nessus Plugin ID 79458

Synopsis

The remote OracleVM host is missing a security update.

Description

The remote OracleVM system is missing necessary patches to address critical security updates :

CVE-2009-0159 Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitrary code via a crafted response.

CVE-2009-1252 Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.

CVE-2009-0021 NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

- fix buffer overflow when parsing Autokey association message (#500783, CVE-2009-1252)

- fix buffer overflow in ntpq (#500783, CVE-2009-0159)

- fix check for malformed signatures (#479698, CVE-2009-0021)

- fix selecting multicast interface (#444106)

- disable kernel discipline when -x option is used (#431729)

- avoid use of uninitialized floating-point values in clock_select (#250838)

- generate man pages from html source, include config man pages (#307271)

- add note about paths and exit codes to ntpd man page (#242925, #246568)

- add section about exit codes to ntpd man page (#319591)

- always return 0 in scriptlets

- pass additional options to ntpdate (#240141)

- fix broadcast client to accept broadcasts on 255.255.255.255 (#226958)

- compile with crypto support on 64bit architectures (#239580)

- add ncurses-devel to buildrequires (#239580)

- exit with nonzero code if ntpd -q did not set clock (#240134)

- fix return codes in init script (#240118)

Solution

Update the affected ntp package.

See Also

https://oss.oracle.com/pipermail/oraclevm-errata/2009-May/000024.html

Plugin Details

Severity: Medium

ID: 79458

File Name: oraclevm_OVMSA-2009-0011.nasl

Version: 1.10

Type: local

Published: 11/26/2014

Updated: 1/14/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:oracle:vm:ntp, cpe:/o:oracle:vm_server:2.1

Required KB Items: Host/local_checks_enabled, Host/OracleVM/release, Host/OracleVM/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 5/27/2009

Vulnerability Publication Date: 1/7/2009

Reference Information

CVE: CVE-2008-5077, CVE-2009-0021, CVE-2009-0159, CVE-2009-1252

BID: 33150, 34481, 35017

CWE: 119, 20, 287