Bug 952606 - (CVE-2015-7871) VUL-0: CVE-2015-7871: ntp: Symmetric association authentication bypass via crypto-NAK
(CVE-2015-7871)
VUL-0: CVE-2015-7871: ntp: Symmetric association authentication bypass via cr...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
:
Depends on:
Blocks: 951608
  Show dependency treegraph
 
Reported: 2015-10-29 10:45 UTC by Andreas Stieger
Modified: 2016-08-01 08:28 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2015-10-29 10:45:09 UTC
+++ This bug was initially created as a clone of Bug #951608 +++

http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_Vulnerabilities

Bug 2941 CVE-2015-7871 NAK to the Future: Symmetric association authentication bypass via crypto-NAK (Cisco ASIG)
http://talosintel.com/reports/TALOS-2015-0069/

https://github.com/ntp-project/ntp/commit/aa44b5835d69d8ee031736bb8ee2730a514edb7d
Comment 1 Swamp Workflow Management 2015-10-29 23:00:15 UTC
bugbot adjusting priority
Comment 2 Reinhard Max 2016-04-06 08:10:14 UTC
Will be fixed by the ongoing upgrade to 4.2.8p6.
Comment 3 Marcus Meissner 2016-08-01 08:28:42 UTC
all released