Get the LinuxSecurity news you want faster with RSS
Powered By
Pardus: Ntp: Security Bypass
Posted by Benjamin D. Thomas
NTP does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.
------------------------------------------------------------------------
Pardus Linux Security Advisory 2009-06 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2009-01-14
Severity: 3
Type: Remote
------------------------------------------------------------------------
Summary
=======
NTP does not properly check the return value from the OpenSSL
EVP_VerifyFinal function, which allows remote attackers to bypass
validation of the certificate chain via a malformed SSL/TLS signature
for DSA and ECDSA keys.
Description
===========
This is a similar vulnerability to CVE-2008-5077.
Affected packages:
Pardus 2008:
ntp-server, all before 4.2.4_p6-9-3
ntp-client, all before 4.2.4_p6-9-3
Resolution
==========
There are update(s) for ntp-server, ntp-client. You can update them via
Package Manager or with a single command from console:
pisi up ntp-server ntp-client
References
==========
* http://bugs.pardus.org.tr/show_bug.cgi?id=8995
* http://www.ocert.org/advisories/ocert-2008-016.html