Executive brief
A vulnerability in the Network Time Protocol daemon (ntpd) could allow a remote attacker to crash the service, causing a denial of service. This software is critical for synchronizing clocks across computer networks, and an outage can disrupt time-sensitive operations and security protocols. The issue is triggered by sending a specific command to the service.
Technical details
A NULL pointer dereference vulnerability exists in the ntpd component of NTP. The flaw is triggered when the service processes a 'reslist' command via ntpdc. A remote, unauthenticated attacker can exploit this to cause the ntpd process to crash, resulting in a denial of service. The vulnerability is present in versions prior to 4.2.8p6 and 4.3.x versions prior to 4.3.90. Users are advised to upgrade to a patched version to mitigate this risk.
Affected products
- NTP Project ntpd before 4.2.8p6, 4.3.x before 4.3.90
Timeline
- 2016-01-19: patched: NTP 4.2.8p6 released
- 2017-01-30: disclosed: NVD publication date
References
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177507.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176434.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00059.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00060.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00020.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00038.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00048.html