Executive brief
The Network Time Protocol (NTP) service, which synchronizes clocks across computer systems, contains a vulnerability when used in broadcast mode. An attacker positioned on the network can capture and resend legitimate time synchronization messages to disrupt the accuracy of system clocks. This can lead to service instability or the failure of security protocols that rely on precise timekeeping.
Technical details
A replay vulnerability exists in NTP's broadcast mode implementation. When NTP is configured to receive time signals via broadcast, it fails to properly validate or uniquely identify packets to prevent them from being re-sent. A man-in-the-middle attacker can sniff legitimate broadcast packets and replay them to a client, potentially causing clock skew or denial of service. This issue is resolved in NTP versions 4.2.8p6 and 4.3.90.
Affected products
- NTP Project NTP Before 4.2.8p6, 4.3.x before 4.3.90
Timeline
- 2016-01-19: advisory: Vendor advisory (NTP Bug 2935) published
- 2017-01-30: disclosed: NVD publication date
References
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00059.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00060.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00020.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00038.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00048.html
- http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00026.html
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00042.html