Junglewise Threat Intelligence

CVE-2016-7428: NTP Project ntpd denial of service in broadcast mode poll interval

CVE-2016-7428 · Severity: medium · CVSS 4.3 · Published 2017-01-13

Technologies: NTP Project Ntpd. Vendors: NTP Project.

Executive brief

A vulnerability in the Network Time Protocol daemon (ntpd) could allow an attacker on the same local network to disrupt time synchronization services. By sending a specially crafted broadcast packet, an attacker can cause the system to reject legitimate time updates, potentially leading to a denial of service for time-sensitive applications. This issue affects systems using NTP broadcast mode for time distribution.

Technical details

A denial of service vulnerability exists in ntpd's handling of broadcast mode packets. The flaw is rooted in how the poll interval is processed within a broadcast packet, which can be manipulated to cause the daemon to reject subsequent legitimate broadcast mode packets. This is classified as an uncontrolled resource consumption issue (CWE-400) affecting the availability of time synchronization. The attack is network-reachable but typically requires the attacker to be on the same adjacent network segment as the broadcast client. The vulnerability is addressed in NTP version 4.2.8p9.

Affected products

  • NTP Project ntpd before 4.2.8p9

Timeline

  • 2016-11-21: advisory: Initial public disclosure by NTP Project
  • 2016-11-21: patched: Fixed in NTP 4.2.8p9
  • 2017-01-13: advisory: NVD publication date

References