Advisories ยป MGASA-2020-0212

Updated ntp packages fix security vulnerability

Publication date: 15 May 2020
Modification date: 15 May 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-11868

Description

The updated packages fix security vulnerabilities including:

ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path
attacker to block unauthenticated synchronization via a server mode packet
with a spoofed source IP address, because transmissions are rescheduled
even when a packet lacks a valid origin timestamp. (CVE-2020-11868)
                

References

SRPMS

7/core