Executive brief
A vulnerability in the Network Time Protocol daemon (ntpd) could allow an attacker on the same local network to disrupt time synchronization services. By sending a specially crafted broadcast packet, an attacker can cause the system to reject legitimate time updates, potentially leading to a denial of service for time-sensitive applications. This issue affects systems using NTP broadcast mode for time distribution.
Technical details
A denial of service vulnerability exists in ntpd's handling of broadcast mode packets. The flaw is rooted in how the poll interval is processed within a broadcast packet, which can be manipulated to cause the daemon to reject subsequent legitimate broadcast mode packets. This is classified as an uncontrolled resource consumption issue (CWE-400) affecting the availability of time synchronization. The attack is network-reachable but typically requires the attacker to be on the same adjacent network segment as the broadcast client. The vulnerability is addressed in NTP version 4.2.8p9.
Affected products
- NTP Project ntpd before 4.2.8p9
Timeline
- 2016-11-21: advisory: Initial public disclosure by NTP Project
- 2016-11-21: patched: Fixed in NTP 4.2.8p9
- 2017-01-13: advisory: NVD publication date
References
- http://nwtime.org/ntp428p9_release/
- http://support.ntp.org/bin/view/Main/NtpBug3113
- http://support.ntp.org/bin/view/Main/SecurityNotice
- http://www.securityfocus.com/bid/94446
- http://www.securitytracker.com/id/1037354
- https://bto.bluecoat.com/security-advisory/sa139
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03706en_us