Junglewise Threat Intelligence

CVE-2015-7977: NTP Project ntpd denial of service via reslist command

CVE-2015-7977 · Severity: medium · CVSS 5.9 · Published 2017-01-30

Executive brief

A vulnerability in the Network Time Protocol daemon (ntpd) could allow a remote attacker to crash the service, causing a denial of service. This software is critical for synchronizing clocks across computer networks, and an outage can disrupt time-sensitive operations and security protocols. The issue is triggered by sending a specific command to the service.

Technical details

A NULL pointer dereference vulnerability exists in the ntpd component of NTP. The flaw is triggered when the service processes a 'reslist' command via ntpdc. A remote, unauthenticated attacker can exploit this to cause the ntpd process to crash, resulting in a denial of service. The vulnerability is present in versions prior to 4.2.8p6 and 4.3.x versions prior to 4.3.90. Users are advised to upgrade to a patched version to mitigate this risk.

Affected products

  • NTP Project ntpd before 4.2.8p6, 4.3.x before 4.3.90

Timeline

  • 2016-01-19: patched: NTP 4.2.8p6 released
  • 2017-01-30: disclosed: NVD publication date

References

Related threats