Junglewise Threat Intelligence

CVE-2016-7434: NTP Project NTP denial of service in read_mru_list

CVE-2016-7434 · Severity: high · CVSS 7.5 · Published 2017-01-13

Vendors: NTP Project.

Executive brief

A vulnerability in the Network Time Protocol (NTP) service, which is used to synchronize clocks across computer systems, could allow a remote attacker to crash the service. By sending a specially crafted request, an attacker can cause the NTP daemon to stop responding, potentially disrupting time-sensitive operations and logging across the network. This issue affects various versions of NTP prior to 4.2.8p9.

Technical details

A denial of service vulnerability exists in the NTP daemon's read_mru_list function due to improper input validation of incoming packets. A remote, unauthenticated attacker can exploit this by sending a specially crafted 'mrulist' query to the NTP server. This triggers a crash in the ntpd process, leading to a complete loss of availability for the time synchronization service. The vulnerability is addressed in NTP version 4.2.8p9.

Affected products

  • NTP Project NTP before 4.2.8p9

Timeline

  • 2016-11-21: disclosed: Initial public disclosure via NTP project bug 3082
  • 2016-11-21: patched: Fixed in NTP 4.2.8p9
  • 2017-01-13: advisory: NVD publication date

References