Executive brief
A vulnerability in the Network Time Protocol (NTP) service, which is used to synchronize clocks across computer networks, could allow a remote attacker to cause a service disruption. By sending a specially crafted request, an attacker can trigger an error that may cause the software to crash or behave unpredictably. This could impact the reliability of time-sensitive operations and logging across the organization.
Technical details
An out-of-bounds read vulnerability exists in the MATCH_ASSOC function of the NTP daemon (ntpd). The flaw is triggered when the software processes an 'addpeer' request containing an excessively large 'hmode' value, leading to an out-of-bounds reference. A remote, unauthenticated attacker can exploit this over the network to cause a denial-of-service condition. The issue is addressed in NTP versions 4.2.8p9 and 4.3.92.
Affected products
- NTP Project NTP Before 4.2.8p9, 4.3.x before 4.3.92
Timeline
- 2016-04-28: advisory: Initial vendor security notice published
- 2017-01-30: disclosed: NVD publication date
References
- http://lists.fedoraproject.org/pipermail/package-announce/2016-May/183647.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184669.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00034.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00037.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00052.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00020.html