CentOS Icon CentOS Logo
CentOS Text
   
  
www.centos.org Forum Index
   CentOS 5 - Security Support
  PCI Compliance NTP

 

 Bottom   Previous Topic   Next Topic
  •  Rate Thread
      Rate this Thread
      Excellent
      Good
      Average
      Bad
      Terrible
Poster Thread
  •  marcus178
      marcus178
PCI Compliance NTP
#1
Newbie
Joined: 2012/1/15
From
Posts: 2
I'm currently try to get Centos 5.7 PCI compliant but keep getting the following in regards to NTP

Description: Possible vulnerability in ntpd Severity: Potential Problem CVE: CVE-2001-0414 Impact: If this vulnerability is present, a remote attacker could gain root access to an affected system. Resolution NTP Software Downloads Upgrade to NTP 4.2.4p8 or higher, or upgrade as designated by Linux vendor

I'm currently on 4.2.2p1 and can't find any way to upgrade. Any suggestions would be welcome.
[Moderator edit: Fix URL.]
Posted on: 2012/1/15 23:10
Create PDF from Post Print
Top
  •  TrevorH
      TrevorH
Re: PCI Compliance NTP
#2
Moderator
Joined: 2009/9/24
From Brighton, UK
Posts: 6376
Generally the way to check is to run

rpm -q --changelog ntp | grep CVE-xxxx-xxxx


but in this case it does not work because it seems that that CVE is so old that it predates Redhat adding CVE numbers to their changelog. However, there is an entry in the changelog

Quote:

* Thu Apr 05 2001 Preston Brown <pbrown@redhat.com>
- security patch for ntpd


and since that's the day after CVE-2001-0414 is dated I think it's a reasonable assumption that it is the fix. I'm also not quite sure of the recommendation to upgrade to 4.2.4 or higher since 4.2.2 was released in 2006 I would really expect it to contain the fix for a security problem reported in 2001! The CVE itself says to upgrade to later than 4.0.99k to fix the problem so this also means that 4.2.2 is OK. What is fixed in 4.2.4p8 is CVE-2009-1252 and that does have an entry in the changelog for RHEL's 4.2.2.

Mods: the link in the OP's post leads nowhere because of a trailing "]"
_________________
Linux/VoIP Systems Administrator
Posted on: 2012/1/16 0:06
Create PDF from Post Print
Top
  •  pschaff
      pschaff
Re: PCI Compliance NTP
#3
Moderator
Joined: 2006/12/13
From Tidewater, Virginia, North America
Posts: 18773
Seems like yet another case of the stupidity of PCI compliance checks that are more concerned with version numbers than actual security. Please point your PCI police to TUV's policy of Backporting of Security Fixes.
_________________
Phil

Recommended reading: FAQ & Readme first ; Search hint: google "your topic site:centos.org"; Smart Questions
Posted on: 2012/1/16 3:37
Create PDF from Post Print
Top
  •  marcus178
      marcus178
Re: PCI Compliance NTP
#4
Newbie
Joined: 2012/1/15
From
Posts: 2
THanks everyone for the advise. I will see how I get on.
Posted on: 2012/1/16 9:38
Create PDF from Post Print
Top
 Top   Previous Topic   Next Topic

 


 You cannot start a new topic.
 You can view topic.
 You cannot reply to posts.
 You cannot edit your posts.
 You cannot delete your posts.
 You cannot add new polls.
 You cannot vote in polls.
 You cannot attach files to posts.
 You cannot post without approval.




"Linux" is a registered trademark of Linus Torvalds. | All other trademarks are property of their respective owners. | All other content is Copyright @ 2004-2009 by the CentOS Project or "each individual contributor (forums, comments, etc.) unless otherwise assigned".| Theme based on a theme by 7dana.com