Junglewise Threat Intelligence

CVE-2015-7979: NTP Project NTP denial of service in broadcast client association

CVE-2015-7979 · Severity: high · CVSS 7.5 · Published 2017-01-30

Vendors: NTP Project.

Executive brief

A vulnerability in the Network Time Protocol (NTP) software can allow a remote attacker to disrupt time synchronization services. By sending specially crafted packets, an attacker can force a client to disconnect from its time server. This can lead to inaccurate system clocks, which may cause security certificate errors, log inconsistencies, and the failure of time-sensitive applications.

Technical details

A denial of service vulnerability exists in NTP's handling of broadcast mode. A remote, unauthenticated attacker can send broadcast packets containing invalid authentication metadata to a client configured to receive broadcast time updates. This causes the client to tear down its existing association with the legitimate time server. The vulnerability affects NTP versions prior to 4.2.8p6 and the 4.3.x development branch prior to 4.3.90. Successful exploitation results in a loss of time synchronization availability for the affected client.

Affected products

  • NTP Project NTP before 4.2.8p6, 4.3.x before 4.3.90

Timeline

  • 2016-01-19: patched: NTP 4.2.8p6 released
  • 2017-01-30: disclosed: NVD publication date

References