Bug 943216 (CVE-2015-5219) - VUL-1: CVE-2015-5219: ntp: infinite loop in sntp processing crafted packet
Summary: VUL-1: CVE-2015-5219: ntp: infinite loop in sntp processing crafted packet
Status: RESOLVED FIXED
Alias: CVE-2015-5219
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Deadline: 2016-12-08
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/142578/
Whiteboard: CVSSv2:SUSE:CVE-2015-5219:3.3:(AV:A/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2015-08-26 07:49 UTC by Sebastian Krahmer
Modified: 2019-05-01 16:51 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sebastian Krahmer 2015-08-26 07:49:51 UTC
Quoting from RH BZ:

"It was discovered that sntp would hang in an infinite loop when a
crafted NTP packet was received, related to the conversion of the
precision value in the packet to double.

Acknowledgements:

This is issue was dicovered by Miroslav Lichvar of Red Hat."

rh#1255118


References:
https://bugzilla.redhat.com/show_bug.cgi?id=1255118
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-5219
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5219
Comment 1 Swamp Workflow Management 2015-08-26 22:00:19 UTC
bugbot adjusting priority
Comment 2 Andreas Stieger 2015-10-02 14:30:12 UTC
Upstream commit:
http://bk1.ntp.org/ntp-dev/?PAGE=patch&REV=51786731Gr4-NOrTBC_a_uXO4wuGhg
https://github.com/ntp-project/ntp/commit/5f295cd05c3c136d39f5b3e500a2d781bdbb59c8

All versions from SLE 11 SP1 up are affected.

Planned update.
Comment 3 SMASH SMASH 2016-01-07 10:24:47 UTC
An update workflow for this issue was started.

This issue was rated as "low".
Please submit fixed packages until "Jan. 14, 2016".

When done, reassign the bug to "security-team@suse.de".
/update/121227/.
Comment 4 SMASH SMASH 2016-01-07 10:25:28 UTC
An update workflow for this issue was started.

This issue was rated as "moderate".
Please submit fixed packages until "Jan. 14, 2016".

When done, reassign the bug to "security-team@suse.de".
/update/121227/.
Comment 5 Marcus Meissner 2016-04-20 11:19:35 UTC
ntp bug 2382

is fixed in 4.2.8-p6
Comment 6 Swamp Workflow Management 2016-05-17 13:11:53 UTC
SUSE-SU-2016:1311-1: An update that solves 30 vulnerabilities and has 6 fixes is now available.

Category: security (important)
Bug References: 782060,784760,905885,910063,916617,920183,920238,926510,936327,937837,942441,942587,943216,943218,944300,946386,951351,951559,951608,951629,954982,956773,962318,962784,962802,962960,962966,962970,962988,962994,962995,962997,963000,963002,975496,975981
CVE References: CVE-2015-5194,CVE-2015-5219,CVE-2015-5300,CVE-2015-7691,CVE-2015-7692,CVE-2015-7701,CVE-2015-7702,CVE-2015-7703,CVE-2015-7704,CVE-2015-7705,CVE-2015-7848,CVE-2015-7849,CVE-2015-7850,CVE-2015-7851,CVE-2015-7852,CVE-2015-7853,CVE-2015-7854,CVE-2015-7855,CVE-2015-7871,CVE-2015-7973,CVE-2015-7974,CVE-2015-7975,CVE-2015-7976,CVE-2015-7977,CVE-2015-7978,CVE-2015-7979,CVE-2015-8138,CVE-2015-8139,CVE-2015-8140,CVE-2015-8158
Sources used:
SUSE OpenStack Cloud 5 (src):    ntp-4.2.8p6-41.1
SUSE Manager Proxy 2.1 (src):    ntp-4.2.8p6-41.1
SUSE Manager 2.1 (src):    ntp-4.2.8p6-41.1
SUSE Linux Enterprise Server 11-SP3-LTSS (src):    ntp-4.2.8p6-41.1
SUSE Linux Enterprise Server 11-SP2-LTSS (src):    ntp-4.2.8p6-41.1, yast2-ntp-client-2.17.14.1-1.12.1
SUSE Linux Enterprise Debuginfo 11-SP3 (src):    ntp-4.2.8p6-41.1
SUSE Linux Enterprise Debuginfo 11-SP2 (src):    ntp-4.2.8p6-41.1
Comment 7 Marcus Meissner 2016-08-01 08:26:55 UTC
all released
Comment 8 Swamp Workflow Management 2016-11-24 15:33:35 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2016-12-08.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/63222
Comment 9 Swamp Workflow Management 2016-12-19 20:08:57 UTC
SUSE-SU-2016:3193-1: An update that solves 12 vulnerabilities and has three fixes is now available.

Category: security (moderate)
Bug References: 1009434,1011377,1011390,1011395,1011398,1011404,1011406,1011411,1011417,943216,956365,981252,988028,992038,992606
CVE References: CVE-2015-5219,CVE-2015-8139,CVE-2015-8140,CVE-2016-7426,CVE-2016-7427,CVE-2016-7428,CVE-2016-7429,CVE-2016-7431,CVE-2016-7433,CVE-2016-7434,CVE-2016-9310,CVE-2016-9311
Sources used:
SUSE Linux Enterprise Server 11-SP4 (src):    ntp-4.2.8p9-57.2
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    ntp-4.2.8p9-57.2
Comment 10 Swamp Workflow Management 2016-12-19 20:12:09 UTC
SUSE-SU-2016:3195-1: An update that solves 10 vulnerabilities and has 5 fixes is now available.

Category: security (moderate)
Bug References: 1009434,1011377,1011390,1011395,1011398,1011404,1011406,1011411,1011417,943216,956365,981252,988028,992038,992606
CVE References: CVE-2015-5219,CVE-2016-7426,CVE-2016-7427,CVE-2016-7428,CVE-2016-7429,CVE-2016-7431,CVE-2016-7433,CVE-2016-7434,CVE-2016-9310,CVE-2016-9311
Sources used:
SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src):    ntp-4.2.8p9-55.1
SUSE Linux Enterprise Server 12-SP2 (src):    ntp-4.2.8p9-55.1
SUSE Linux Enterprise Server 12-SP1 (src):    ntp-4.2.8p9-55.1
SUSE Linux Enterprise Desktop 12-SP2 (src):    ntp-4.2.8p9-55.1
SUSE Linux Enterprise Desktop 12-SP1 (src):    ntp-4.2.8p9-55.1
Comment 11 Swamp Workflow Management 2016-12-19 20:14:36 UTC
SUSE-SU-2016:3196-1: An update that solves 10 vulnerabilities and has 5 fixes is now available.

Category: security (moderate)
Bug References: 1009434,1011377,1011390,1011395,1011398,1011404,1011406,1011411,1011417,943216,956365,981252,988028,992038,992606
CVE References: CVE-2015-5219,CVE-2016-7426,CVE-2016-7427,CVE-2016-7428,CVE-2016-7429,CVE-2016-7431,CVE-2016-7433,CVE-2016-7434,CVE-2016-9310,CVE-2016-9311
Sources used:
SUSE Linux Enterprise Server for SAP 12 (src):    ntp-4.2.8p9-46.18.1
SUSE Linux Enterprise Server 12-LTSS (src):    ntp-4.2.8p9-46.18.1
Comment 12 Swamp Workflow Management 2016-12-28 15:08:39 UTC
openSUSE-SU-2016:3280-1: An update that solves 10 vulnerabilities and has 5 fixes is now available.

Category: security (moderate)
Bug References: 1009434,1011377,1011390,1011395,1011398,1011404,1011406,1011411,1011417,943216,956365,981252,988028,992038,992606
CVE References: CVE-2015-5219,CVE-2016-7426,CVE-2016-7427,CVE-2016-7428,CVE-2016-7429,CVE-2016-7431,CVE-2016-7433,CVE-2016-7434,CVE-2016-9310,CVE-2016-9311
Sources used:
openSUSE Leap 42.2 (src):    ntp-4.2.8p9-27.1
openSUSE Leap 42.1 (src):    ntp-4.2.8p9-27.1
Comment 13 Swamp Workflow Management 2017-01-23 15:10:46 UTC
SUSE-SU-2017:0255-1: An update that solves 12 vulnerabilities and has three fixes is now available.

Category: security (moderate)
Bug References: 1009434,1011377,1011390,1011395,1011398,1011404,1011406,1011411,1011417,943216,956365,981252,988028,992038,992606
CVE References: CVE-2015-5219,CVE-2015-8139,CVE-2015-8140,CVE-2016-7426,CVE-2016-7427,CVE-2016-7428,CVE-2016-7429,CVE-2016-7431,CVE-2016-7433,CVE-2016-7434,CVE-2016-9310,CVE-2016-9311
Sources used:
SUSE OpenStack Cloud 5 (src):    ntp-4.2.8p9-48.9.1
SUSE Manager Proxy 2.1 (src):    ntp-4.2.8p9-48.9.1
SUSE Manager 2.1 (src):    ntp-4.2.8p9-48.9.1
SUSE Linux Enterprise Server 11-SP3-LTSS (src):    ntp-4.2.8p9-48.9.1
SUSE Linux Enterprise Server 11-SP2-LTSS (src):    ntp-4.2.8p9-48.9.1
SUSE Linux Enterprise Point of Sale 11-SP3 (src):    ntp-4.2.8p9-48.9.1
SUSE Linux Enterprise Debuginfo 11-SP3 (src):    ntp-4.2.8p9-48.9.1
SUSE Linux Enterprise Debuginfo 11-SP2 (src):    ntp-4.2.8p9-48.9.1