what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Cisco Security Advisory 20141222-ntpd

Cisco Security Advisory 20141222-ntpd
Posted Dec 24, 2014
Authored by Cisco Systems | Site cisco.com

Cisco Security Advisory - Multiple Cisco products incorporate a version of the ntpd package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to execute arbitrary code or create a denial of service (DoS) condition. On December 19, 2014, NTP.org and US-CERT released security advisories detailing two issues regarding weak cryptographic pseudorandom number generation (PRNG), three buffer overflow vulnerabilities, and an unhandled error condition with an unknown impact. Cisco will release free software updates that address these vulnerabilities. Workarounds that mitigate these vulnerabilities are available.

tags | advisory, remote, denial of service, overflow, arbitrary, vulnerability
systems | cisco
advisories | CVE-2014-9293, CVE-2014-9294, CVE-2014-9295, CVE-2014-9296
SHA-256 | 5dbade7a53bf1ca9ac25f9e8c3be3931a5da81f0c75dd71cb6377e3ee36e48ba

Cisco Security Advisory 20141222-ntpd

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Cisco Security Advisory: Multiple Vulnerabilities in ntpd Affecting Cisco Products

Advisory ID: cisco-sa-20141222-ntpd

Revision 1.1

Last Updated 2014 December 23 13:37 UTC (GMT)

For Public Release 2014 December 22 16:00 UTC (GMT)

+---------------------------------------------------------------------

Summary
=======

Multiple Cisco products incorporate a version of the ntpd package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to execute arbitrary code or create a denial of service (DoS) condition.

On December 19, 2014, NTP.org and US-CERT released security advisories detailing two issues regarding weak cryptographic pseudorandom number generation (PRNG), three buffer overflow vulnerabilities, and an unhandled error condition with an unknown impact. The vulnerabilities are referenced in this document as follows:

* CVE-2014-9293: Weak Default Key in config_auth()
* CVE-2014-9294: Noncryptographic Random Number Generator with Weak Seed Used by ntp-keygen to Generate Symmetric Keys
* CVE-2014-9295: Multiple Buffer Overflow Vulnerabilities in ntpd
* CVE-2014-9296: ntpd receive(): Missing Return on Error

This advisory will be updated as additional information becomes available.

Cisco will release free software updates that address these vulnerabilities.

Workarounds that mitigate these vulnerabilities are available.

This advisory is available at the following link:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20141222-ntpd

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (SunOS)

iQIVAwUBVJn5jopI1I6i1Mx3AQIgig/+Pwng8NnetF1akKCYNBHhmBPp+TZsILzD
gchFJT9pewtbL+tjWy7lWerXfFS8VrSd4EqJM5T7dawuw7I6EOUusSsyC9f1boIT
iqgL204OwH92C8VVcHfFoQn7A5HVGcJDtriwZvNt+nrsEPUEkMyB6E1cQPe3lQHg
yeGQRnl8JH7E4Teo2HttmLUAWQ8bQfKXzS1R5aT53TXTR7Fnwl3oc/DApAZu7KiG
C5MF3ZCNXF8PxtnKlo6rp38CofzM6GYhUgFngC3yGlQPKNuAr8UeoZAsDhkbSTMH
XU6RPZW9O+GOTIeWGj3TH+ywE8D7gNwRHy3R20h6edY29w+lq+uI2DQAzJfx+0Ut
Sb2362a2vPinrSEAMZUMZ8HA90g+uFt2PzWE+/mX/iQ9R0wqoahwF5L5f5TOdhaE
xqydVm/p4dgUx4axgDoTES7rANheGV+87xHYBgIhfynEUBB6BCrzAaFndgMti8h1
r8kmNLzJNV6A13LPoimvtec+WFQoEFlmHj2cpPG1wGsogeMrDck0h3t6VagiSh6T
w9rS2unkcTekTe/r+rUcDG2FlujhDlhv8hmtwfPO8OIUwo4W1NaTDMzHXobfG851
piw3zjAvMySLWZK9BswmaIwL7HnRap9xtmDOGiPGEi1AqI8QMkzEXJAYHMbmX/IO
FSCtrcV2J2o=
=Ohet
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    28 Files
  • 16
    Jul 16th
    6 Files
  • 17
    Jul 17th
    34 Files
  • 18
    Jul 18th
    6 Files
  • 19
    Jul 19th
    34 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    19 Files
  • 23
    Jul 23rd
    17 Files
  • 24
    Jul 24th
    47 Files
  • 25
    Jul 25th
    31 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close