Junglewise Threat Intelligence

CVE-2016-7427: NTP Project ntpd denial of service in broadcast mode replay prevention

CVE-2016-7427 · Severity: medium · CVSS 4.3 · Published 2017-01-13

Technologies: NTP Project Ntpd. Vendors: NTP Project.

Executive brief

A vulnerability in the Network Time Protocol (NTP) daemon could allow an attacker on the same local network to disrupt time synchronization services. By sending a specially crafted packet, an attacker can trigger a flaw in how the software prevents old messages from being replayed, causing the system to reject legitimate time updates. This can lead to inaccurate system clocks, which may impact security logs, scheduled tasks, and other time-sensitive business operations.

Technical details

A denial of service vulnerability exists in the broadcast mode replay prevention mechanism of ntpd. The root cause is an improper handling of crafted broadcast mode packets which can trigger the replay protection logic prematurely or incorrectly. An attacker on the same network segment (adjacent) can send a malicious packet that causes the daemon to reject subsequent legitimate broadcast mode packets. This results in a loss of time synchronization for clients relying on broadcast mode. The issue is addressed in NTP version 4.2.8p9.

Affected products

  • NTP Project ntpd Before 4.2.8p9

Timeline

  • 2016-11-21: advisory: Initial security advisory released by NTP Project
  • 2017-01-13: disclosed: NVD publication date
  • 2016-11-21: patched: Fixed in NTP 4.2.8p9

References