Executive brief
A vulnerability in the Network Time Protocol (NTP) service, which synchronizes clocks across computer networks, could allow an attacker to disrupt the service. By sending a specially crafted message, an attacker can change internal security keys, effectively locking out legitimate administrators from managing the service. This results in a denial of service for administrative functions until the software is restarted.
Technical details
A regression of CVE-2016-2516 in the NTP daemon (ntpd) allows remote attackers to perform a denial of service against authentication mechanisms. If ntpd is explicitly configured to allow remote configuration, an attacker with knowledge of the existing controlkey or requestkey can send a crafted packet that modifies the trustedkey, controlkey, or requestkey values. This improper input validation prevents subsequent legitimate authentication attempts until the ntpd process is restarted. The attack requires the 'remote configuration' feature to be enabled, which is not a default setting. The issue is resolved in NTP versions 4.2.8p7 and 4.3.92.
Affected products
- NTP Project ntp before 4.2.8p7, 4.3.x before 4.3.92
Timeline
- 2016-04-27: patched: FreeBSD released patches for affected versions.
- 2016-04-29: advisory: FreeBSD Security Advisory FreeBSD-SA-16:16.ntp published.
- 2017-01-30: disclosed: NVD publication date.
References
- http://support.ntp.org/bin/view/Main/NtpBug3010
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/88189
- http://www.securitytracker.com/id/1035705
- https://security.freebsd.org/advisories/FreeBSD-SA-16:16.ntp.asc
- https://security.gentoo.org/glsa/201607-15
- https://security.netapp.com/advisory/ntap-20171004-0002/