Executive brief
A vulnerability exists in the Network Time Protocol (NTP) service, which is used to synchronize clocks across computer networks. An attacker with basic access could use a specially crafted filename in a configuration command to cause unintended behavior. This could potentially allow unauthorized changes to system files or configuration, impacting the integrity of the server.
Technical details
The ntpq 'saveconfig' command in multiple versions of NTP fails to properly sanitize or filter special characters in filenames. An authenticated remote attacker can exploit this by providing a maliciously crafted filename to the command. This vulnerability is classified under CWE-254 (Security Features) and can lead to unauthorized file modification or other unspecified impacts. The issue is resolved in NTP version 4.2.8p6 and later.
Affected products
- NTP Project NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, 4.3.77
Timeline
- 2016-01-20: advisory: Vendor advisory (NTP Bug 2938) published
- 2017-01-30: disclosed: NVD publication date
References
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00059.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00060.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00020.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00038.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00048.html
- http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00026.html
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00042.html