Executive brief
A vulnerability in the Network Time Protocol (NTP) software can allow an attacker to disrupt time synchronization on a server. NTP is a critical service used to keep computer clocks accurate across a network. By sending specially crafted messages, an attacker can trick the system into blocking legitimate time updates, potentially causing system clocks to drift and leading to failures in security protocols or scheduled tasks.
Technical details
A vulnerability exists in NTP (ntpd) where rate limiting for all associations, when enabled, is incorrectly applied to responses received from configured upstream time sources. A remote, unauthenticated attacker can exploit this by sending spoofed NTP responses that appear to come from the legitimate configured sources. This triggers the rate-limiting mechanism on the victim's ntpd instance, causing it to reject subsequent valid responses from the actual time sources. This results in a denial of service (DoS) where the system fails to synchronize its clock. The issue is resolved in NTP version 4.2.8p9.
Affected products
- NTP Project NTP before 4.2.8p9
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
Timeline
- 2016-11-21: advisory: SecurityFocus BID 94451 published
- 2016-11-21: patched: NTP 4.2.8p9 released
- 2017-01-13: disclosed: NVD publication date
- 2017-02-06: advisory: Red Hat security advisory RHSA-2017:0252 issued
References
- http://nwtime.org/ntp428p9_release/
- http://rhn.redhat.com/errata/RHSA-2017-0252.html
- http://support.ntp.org/bin/view/Main/NtpBug3071
- http://support.ntp.org/bin/view/Main/SecurityNotice
- http://www.securityfocus.com/bid/94451
- http://www.securitytracker.com/id/1037354
- https://bto.bluecoat.com/security-advisory/sa139