Executive brief
A vulnerability in the Network Time Protocol (NTP) service, which is used to synchronize clocks across computer systems, could allow a remote attacker to crash the service. By sending a specially crafted request, an attacker can cause the NTP daemon to stop responding, potentially disrupting time-sensitive operations and logging across the network. This issue affects various versions of NTP prior to 4.2.8p9.
Technical details
A denial of service vulnerability exists in the NTP daemon's read_mru_list function due to improper input validation of incoming packets. A remote, unauthenticated attacker can exploit this by sending a specially crafted 'mrulist' query to the NTP server. This triggers a crash in the ntpd process, leading to a complete loss of availability for the time synchronization service. The vulnerability is addressed in NTP version 4.2.8p9.
Affected products
- NTP Project NTP before 4.2.8p9
Timeline
- 2016-11-21: disclosed: Initial public disclosure via NTP project bug 3082
- 2016-11-21: patched: Fixed in NTP 4.2.8p9
- 2017-01-13: advisory: NVD publication date
References
- http://nwtime.org/ntp428p9_release/
- http://support.ntp.org/bin/view/Main/NtpBug3082
- http://support.ntp.org/bin/view/Main/SecurityNotice
- http://www.securityfocus.com/bid/94448
- http://www.securitytracker.com/id/1037354
- https://bto.bluecoat.com/security-advisory/sa139
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03706en_us