Junglewise Threat Intelligence

CVE-2016-7433: NTP Project NTP denial of service in initial sync calculations

CVE-2016-7433 · Severity: medium · CVSS 5.3 · Published 2017-01-13

Technologies: Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 6, Ntp. Vendors: Red Hat, Huawei, NTP Project, Ntp.

Executive brief

A vulnerability in the Network Time Protocol (NTP) software, which is used to synchronize clocks across computer networks, could allow a remote attacker to disrupt time synchronization. By sending specially crafted network packets, an attacker could cause the service to crash or fail to sync correctly, potentially leading to operational issues for systems that rely on accurate time for security logging or transaction processing.

Technical details

The vulnerability exists in the Network Time Protocol daemon (ntpd) due to an incorrect implementation of root distance calculations. Specifically, a previous fix for a different bug (Bug 2085) resulted in a regression where the root distance calculation failed to include peer dispersion. A remote, unauthenticated attacker can exploit this by sending specially crafted spoofed packets to the target host. Successful exploitation can cause ntpd to fail to synchronize with its time sources or, in certain cases, cause the daemon to crash, resulting in a denial of service (DoS). The issue is resolved in NTP version 4.2.8p9.

Affected products

  • NTP Project NTP before 4.2.8p9
  • Red Hat Enterprise Linux 6
  • Red Hat Enterprise Linux 7
  • Huawei FusionAccess
  • Huawei FusionSphere OpenStack

Timeline

  • 2016-11-21: patched: NTP 4.2.8p9 released
  • 2017-01-13: disclosed: NVD publication date

References

Related threats