Junglewise Threat Intelligence

CVE-2016-7429: NTP Project ntp denial of service in interface selection

CVE-2016-7429 · Severity: low · CVSS 3.7 · Published 2017-01-13

Technologies: Ntp, Red Hat Enterprise Linux. Vendors: NTP Project, Ntp, Red Hat.

Executive brief

A vulnerability in the Network Time Protocol (NTP) software can allow a remote attacker to disrupt time synchronization on servers with multiple network interfaces. By sending specially crafted responses, an attacker can prevent a system from communicating with its legitimate time sources. This can lead to inaccurate system clocks, which may impact time-sensitive operations, logging, and security protocols.

Technical details

A flaw exists in ntpd's handling of server responses on hosts configured with multiple network interfaces. When a response is received from a source, NTP incorrectly updates the peer structure to the interface on which the response was received. A remote attacker can exploit this by sending a spoofed response for a legitimate source to an interface that the source does not actually use. This causes ntpd to fail to synchronize with the legitimate source, resulting in a denial of service. The vulnerability is addressed in NTP version 4.2.8p9.

Affected products

  • NTP Project ntp before 4.2.8p9
  • Red Hat Enterprise Linux 6, 7

Timeline

  • 2016-11-21: advisory: NTP Project release notes for 4.2.8p9
  • 2017-01-13: disclosed: NVD publication date
  • 2017-02-06: patched: Red Hat issued security updates RHSA-2017:0252

References

Related threats