Executive brief
The Network Time Protocol (NTP) service, which synchronizes clocks across computer networks, contains a flaw in how it validates the origin of time updates. A remote attacker can bypass security checks by sending a specially crafted packet with a zeroed-out timestamp. This could allow an attacker to interfere with the accuracy of system time, potentially impacting time-sensitive operations and security logs.
Technical details
A regression in the timestamp validation logic of ntpd (originally intended to fix CVE-2015-8138) allows remote attackers to bypass origin timestamp protection. By sending an NTP packet with an origin timestamp of zero, an attacker can bypass the mechanism designed to ensure that a response corresponds to a legitimate recent request. This improper input validation (CWE-20) allows for unauthorized modification of time data. The vulnerability is resolved in NTP version 4.2.8p9.
Affected products
- NTP Project ntpd before 4.2.8p9
- Huawei FusionAccess V100R006C00B021, V100R006C00RC2, V100R006C10
- Huawei FusionSphere OpenStack V100R005C00
- Huawei OceanStor UDS V100R002C00LVDF01
- Huawei RH5885 V3 V100R003C01, V100R003C01SPC200
- Huawei eSpace VCN3000 V100R002C00SPC108, V100R002C10SPC108
- Huawei iBMC V100R002C10
Timeline
- 2016-11-21: patched: NTP 4.2.8p9 released
- 2017-01-13: disclosed: NVD publication date
- 2017-11-29: advisory: Huawei secondary advisory published
References
- http://lists.opensuse.org/opensuse-updates/2016-12/msg00153.html
- http://nwtime.org/ntp428p9_release/
- http://packetstormsecurity.com/files/140240/FreeBSD-Security-Advisory-FreeBSD-SA-16.39.ntp.html
- http://support.ntp.org/bin/view/Main/NtpBug3102
- http://support.ntp.org/bin/view/Main/SecurityNotice
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171129-01-ntpd-en
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html