Date: Wed, 24 Dec 2014 17:12:04 +0000 From: Glen Barber <gjb@FreeBSD.org> To: Andrei <az@azsupport.com> Cc: freebsd-security@freebsd.org Subject: Re: FreeBSD Security Advisory FreeBSD-SA-14:31.ntp Message-ID: <20141224171203.GF40485@hub.FreeBSD.org> In-Reply-To: <20141224174216.6fd47466@azsupport.com> References: <20141223233310.098C54BB6@nine.des.no> <20141224174216.6fd47466@azsupport.com>
next in thread | previous in thread | raw e-mail | index | archive | help
--cHMo6Wbp1wrKhbfi Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Wed, Dec 24, 2014 at 05:42:16PM +0100, Andrei wrote: > On Wed, 24 Dec 2014 00:33:09 +0100 (CET) > FreeBSD Security Advisories <security-advisories@freebsd.org> wrote: >=20 > > No workaround is available, but systems not running ntpd(8) are not > > affected. Because the issue may lead to remote root compromise, the > > FreeBSD Security Team recommends system administrators to firewall NTP > > ports, namely tcp/123 and udp/123 when it is not clear that all > > systems have been patched or have ntpd(8) stopped. >=20 > Why tcp/123? >=20 gjb@nucleus:~ % grep -i ^ntp /etc/services ntp 123/tcp #Network Time Protocol ntp 123/udp #Network Time Protocol Glen --cHMo6Wbp1wrKhbfi Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJUmvPaAAoJEAMUWKVHj+KTGP4QAJqyVNbuXhMudg3FiqKFLyQ5 VOADkEU/MV5V99wvCKd8czG09FHmSNtpc2XZX3ElzlpJu0/j17ZsZzgXDrodUhqI pzSkX+OX2segjV4mOyjvJnaOtnFGq9TvwRnW3hTZ3yjRtoYPbwdydFY5W22Jmu9V DK7DkJAY9wj7EcbOD36j7jcfOS5h1LH4XKXkCC7JcNvUTy6IHWbw9JZUlyVSVmdA RhjHE+fx7uUInpT/CLTvW+Hrm+sh/ZpPoIt0poOmy4dBgZAmerSby7NZ8CETkU+6 u0gOC+zITzjrU7/C12x92xXbpsquxa0qt+vvUVlBgPEmFdV0uKVej3Y//h0TrhRL HxaOHHk5cSG0DOr1er2tfXM9FYKrtONZsA1qFuWNip1joR6jqy8ZU/l4FTHkVFdV p2Evhv5VhBq9/jMpfiUcANC/wChxYCFlqNvzMsvnAdlUGafc4JqHPsr5JmlBOZvr YkXFBL31L5kguBtaRcUIwwFM9Giu51MqvSdebYYIwMz0NEQ8gYbt+72wNQMqHVfT H0ITGtxztvJQ36P2dPHBE5yoXh64DblDct+UnRNIqyOKEQ+SueJy9J97xRaXUbUN CCfdCCJJjXrx1J9YrdQwYknnGX9gm0U081/8iZ68kI4ayWodST4BZ9R463Q33dWq 7BuI2ObCJ7ROYMCCkOdq =BzVB -----END PGP SIGNATURE----- --cHMo6Wbp1wrKhbfi--
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20141224171203.GF40485>