Executive brief
A vulnerability in the Network Time Protocol (NTP) service, which synchronizes clocks across computer networks, could allow an attacker to crash the service. By sending a specific command, a remote attacker can cause the system to exhaust its memory resources, leading to a denial of service. This can disrupt time-sensitive operations and security protocols that rely on accurate system clocks.
Technical details
A stack exhaustion vulnerability exists in the NTP daemon (ntpd) when processing 'ntpdc relist' commands. The flaw is rooted in the recursive traversal of the restriction list; an attacker can trigger this recursion remotely without authentication. Successful exploitation leads to a crash of the ntpd process, resulting in a denial of service. This issue affects NTP versions prior to 4.2.8p6 and the 4.3 development branch prior to 4.3.90. Users are advised to upgrade to NTP 4.2.8p6 or later.
Affected products
- NTP Project NTP 4.2.8p6 and earlier, 4.3.0 through 4.3.89
Timeline
- 2016-01-27: advisory: Cisco security advisory published
- 2017-01-30: disclosed: NVD publication date
References
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177507.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176434.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00059.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00060.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00020.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00038.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00048.html