Get the LinuxSecurity news you want faster with RSS
Powered By
Pardus: Ntp: Buffer Overflow
Posted by Benjamin D. Thomas
Apple discovered a stack-based buffer overflow in the ntpq program.
------------------------------------------------------------------------
Pardus Linux Security Advisory 2009-55 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2009-04-12
Severity: 2
Type: Remote
------------------------------------------------------------------------
Summary
=======
Apple discovered a stack-based buffer overflow in the ntpq program.
Description
===========
When the ntpq program is used to request peer information from a remote
time server, a maliciously crafted response may lead to an unexpected
application termination or arbitrary code execution.
The buffer overflow is limited to two bytes, so a code execution impact
is unlikely, but this is dependent on the stack layout generated by cc.
Affected packages:
Pardus 2008:
ntp-client, all before 4.2.4_p6-10-4
ntp-server, all before 4.2.4_p6-10-4
Resolution
==========
There are update(s) for ntp-client, ntp-server. You can update them via
Package Manager or with a single command from console:
pisi up ntp-client ntp-server
References
==========
* http://bugs.pardus.org.tr/show_bug.cgi?id=9532
* https://support.ntp.org/bugs/show_bug.cgi?id=1144