Junglewise Threat Intelligence

CVE-2015-8138: NTP Project ntpd origin timestamp validation bypass

CVE-2015-8138 · Severity: medium · CVSS 5.3 · Published 2017-01-30

Executive brief

The Network Time Protocol (NTP) service, which synchronizes clocks across computer networks, contains a security flaw in how it validates incoming packets. An attacker can send a specially crafted packet to bypass security checks that ensure time updates are coming from a legitimate source. This could allow an unauthorized party to potentially influence or disrupt the time synchronization of affected systems.

Technical details

A vulnerability in the Network Time Protocol (NTP) daemon (ntpd) involves improper input validation of the origin timestamp field. Remote, unauthenticated attackers can bypass the origin timestamp validation mechanism by sending a packet where the origin timestamp is set to zero. This bypass allows an attacker to potentially inject unauthorized time data or interfere with the synchronization process. The issue is resolved in NTP versions 4.2.8p6 and 4.3.90.

Affected products

  • NTP Project ntpd 4.2.8 before 4.2.8p6, 4.3.x before 4.3.90

Timeline

  • 2016-01-19: patched: NTP 4.2.8p6 released
  • 2017-01-30: disclosed: NVD publication date

References

Related threats