www.centos.org Forum Index CentOS 5 - Security Support PCI Compliance NTP
|
Bottom Previous Topic Next Topic |
| |
|
|
|---|
| Poster | Thread |
|---|
|
PCI Compliance NTP | #1 |
|
|---|---|---|---|
|
Newbie
![]()
Joined: 2012/1/15
From
Posts: 2
|
I'm currently try to get Centos 5.7 PCI compliant but keep getting the following in regards to NTP
Description: Possible vulnerability in ntpd Severity: Potential Problem CVE: CVE-2001-0414 Impact: If this vulnerability is present, a remote attacker could gain root access to an affected system. Resolution NTP Software Downloads Upgrade to NTP 4.2.4p8 or higher, or upgrade as designated by Linux vendor I'm currently on 4.2.2p1 and can't find any way to upgrade. Any suggestions would be welcome. [Moderator edit: Fix URL.] |
||
Posted on: 2012/1/15 23:10
|
|||
|
Re: PCI Compliance NTP | #2 |
|
|---|---|---|---|
|
Moderator
![]()
Joined: 2009/9/24
From Brighton, UK
Posts: 6376
|
Generally the way to check is to run
but in this case it does not work because it seems that that CVE is so old that it predates Redhat adding CVE numbers to their changelog. However, there is an entry in the changelog Quote:
and since that's the day after CVE-2001-0414 is dated I think it's a reasonable assumption that it is the fix. I'm also not quite sure of the recommendation to upgrade to 4.2.4 or higher since 4.2.2 was released in 2006 I would really expect it to contain the fix for a security problem reported in 2001! The CVE itself says to upgrade to later than 4.0.99k to fix the problem so this also means that 4.2.2 is OK. What is fixed in 4.2.4p8 is CVE-2009-1252 and that does have an entry in the changelog for RHEL's 4.2.2. Mods: the link in the OP's post leads nowhere because of a trailing "]" |
||
|
_________________
Linux/VoIP Systems Administrator |
|||
Posted on: 2012/1/16 0:06
|
|||
|
Re: PCI Compliance NTP | #3 |
|
|---|---|---|---|
|
Moderator
![]()
Joined: 2006/12/13
From Tidewater, Virginia, North America
Posts: 18773
|
Seems like yet another case of the stupidity of PCI compliance checks that are more concerned with version numbers than actual security. Please point your PCI police to TUV's policy of Backporting of Security Fixes.
|
||
|
_________________
Phil Recommended reading: FAQ & Readme first ; Search hint: google "your topic site:centos.org"; Smart Questions |
|||
Posted on: 2012/1/16 3:37
|
|||
|
Re: PCI Compliance NTP | #4 |
|
|---|---|---|---|
|
Newbie
![]()
Joined: 2012/1/15
From
Posts: 2
|
THanks everyone for the advise. I will see how I get on.
|
||
Posted on: 2012/1/16 9:38
|
|||
Top Previous Topic Next Topic |
|



Topic options
Print Topic
Threaded
Newest First
marcus178




You cannot start a new topic.
You can view topic.