Security Finder

You can use the Security Finder to search for security issues and their impact on Riverbed products. This page is continuously updated, displaying the most current public security issues first. The search box can be used to look up records by specific CVE numbers or relevant search word, e.g. Apache, 8.5.0, Workaround. For additional search tips, refer to article S16165. Security issues listed here are categorized into three groups: fixed, workaround recommended and not applicable.

For general security topics, security best practices and other security related topics, try performing a general search.

BETA FEATURE: This feature is currently under development and is considered Beta Software. We are still enhancing the features and results so please exercise caution when interpreting and implementing the results. If you have any questions, please open a case with Riverbed Support. If you have feedback for this tool, please send it to supportfeedback@riverbed.com.

Riverbed Technology is committed to protecting customers against vulnerabilities in our supported products. Vulnerabilities are addressed in accordance to the software support policy. https://support.riverbed.com/content/support/about_support/end_of_life_policy.html

For search tips, read article S16165.

CVE-2014-9293, CVE-2014-9294, CVE-2014-9295, CVE-2014-9296: NTP: Network Time Protocol cumulative security update RHSA-2014:2024-1 (Bug #222718)

Product
SteelHead (Appliance)
Fixed in Version:
steelhead 9.0.1, steelhead 9.1.0, steelhead 8.6.3
Last Modified:
2015-08-27
Summary
Details:

This security update addresses the following issues:

CVE-2014-9293: It was found that the ntpd protocol automatically generated weak keys for internal use if no ntpdc request authentication key was specified in the ntp.conf configuration file. A remote attacker, able to match the configured IP restrictions, could guess the generated key and possibly use it to send an ntpdc query or configuration requests.

CVE-2014-9294: It was found that the ntp-keygen program used a weak method for generating MD5 keys. This could possibly allow an attacker to guess generated MD5 keys that could then be used to spoof an NTP client or server.

CVE-2014-9295: Multiple buffer overflow flaws were discovered in the ntpd crypto_recv(), ctl_putdata(), and configure() functions. A remote attacker could use either of these flaws to send a specially crafted request packet that could crash ntpd, or potentially, execute arbitrary code with the privileges of the NTP user. 

CVE-2014-9296: A missing return statement in the receive() function could potentially allow a remote attacker to bypass the NTP authentication mechanism.

Fix:

RiOS, in its default setting, is not impacted by any of the above issues. However, the NTP module has been upgraded to a version that addresses these issues.

Recommendation:

Upgrade to a v9.1 of RiOS that has the updated NTP module.