From owner-freebsd-security@FreeBSD.ORG Wed Dec 24 17:12:16 2014 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from hub.FreeBSD.org (hub.freebsd.org [IPv6:2001:1900:2254:206c::16:88]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id F2C20D25; Wed, 24 Dec 2014 17:12:15 +0000 (UTC) Date: Wed, 24 Dec 2014 17:12:04 +0000 From: Glen Barber To: Andrei Subject: Re: FreeBSD Security Advisory FreeBSD-SA-14:31.ntp Message-ID: <20141224171203.GF40485@hub.FreeBSD.org> References: <20141223233310.098C54BB6@nine.des.no> <20141224174216.6fd47466@azsupport.com> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="cHMo6Wbp1wrKhbfi" Content-Disposition: inline In-Reply-To: <20141224174216.6fd47466@azsupport.com> X-Operating-System: FreeBSD 11.0-CURRENT amd64 X-SCUD-Definition: Sudden Completely Unexpected Dataloss X-SULE-Definition: Sudden Unexpected Learning Event User-Agent: Mutt/1.5.23 (2014-03-12) Cc: freebsd-security@freebsd.org X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 24 Dec 2014 17:12:16 -0000 --cHMo6Wbp1wrKhbfi Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Wed, Dec 24, 2014 at 05:42:16PM +0100, Andrei wrote: > On Wed, 24 Dec 2014 00:33:09 +0100 (CET) > FreeBSD Security Advisories wrote: >=20 > > No workaround is available, but systems not running ntpd(8) are not > > affected. Because the issue may lead to remote root compromise, the > > FreeBSD Security Team recommends system administrators to firewall NTP > > ports, namely tcp/123 and udp/123 when it is not clear that all > > systems have been patched or have ntpd(8) stopped. >=20 > Why tcp/123? >=20 gjb@nucleus:~ % grep -i ^ntp /etc/services ntp 123/tcp #Network Time Protocol ntp 123/udp #Network Time Protocol Glen --cHMo6Wbp1wrKhbfi Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJUmvPaAAoJEAMUWKVHj+KTGP4QAJqyVNbuXhMudg3FiqKFLyQ5 VOADkEU/MV5V99wvCKd8czG09FHmSNtpc2XZX3ElzlpJu0/j17ZsZzgXDrodUhqI pzSkX+OX2segjV4mOyjvJnaOtnFGq9TvwRnW3hTZ3yjRtoYPbwdydFY5W22Jmu9V DK7DkJAY9wj7EcbOD36j7jcfOS5h1LH4XKXkCC7JcNvUTy6IHWbw9JZUlyVSVmdA RhjHE+fx7uUInpT/CLTvW+Hrm+sh/ZpPoIt0poOmy4dBgZAmerSby7NZ8CETkU+6 u0gOC+zITzjrU7/C12x92xXbpsquxa0qt+vvUVlBgPEmFdV0uKVej3Y//h0TrhRL HxaOHHk5cSG0DOr1er2tfXM9FYKrtONZsA1qFuWNip1joR6jqy8ZU/l4FTHkVFdV p2Evhv5VhBq9/jMpfiUcANC/wChxYCFlqNvzMsvnAdlUGafc4JqHPsr5JmlBOZvr YkXFBL31L5kguBtaRcUIwwFM9Giu51MqvSdebYYIwMz0NEQ8gYbt+72wNQMqHVfT H0ITGtxztvJQ36P2dPHBE5yoXh64DblDct+UnRNIqyOKEQ+SueJy9J97xRaXUbUN CCfdCCJJjXrx1J9YrdQwYknnGX9gm0U081/8iZ68kI4ayWodST4BZ9R463Q33dWq 7BuI2ObCJ7ROYMCCkOdq =BzVB -----END PGP SIGNATURE----- --cHMo6Wbp1wrKhbfi--