Junglewise Threat Intelligence

CVE-2016-9310: NTP ntpd information disclosure and DDoS vector in mode 6 control functionality

CVE-2016-9310 · Severity: medium · CVSS 6.5 · Published 2017-01-13

Executive brief

A vulnerability exists in the Network Time Protocol (NTP) daemon, which is used to synchronize clocks across computer networks. A remote attacker can exploit this flaw to manipulate system monitoring 'traps' or use the service to launch distributed denial-of-service (DDoS) amplification attacks. This could lead to unauthorized information disclosure or service disruptions for the affected organization and third parties.

Technical details

A vulnerability in the control mode (mode 6) functionality of ntpd allows unauthenticated remote attackers to manipulate trap settings. By sending specially crafted mode 6 control packets, an attacker can set or unset traps, which can be leveraged for information disclosure or as a vector for DDoS amplification attacks. The root cause is insufficient validation of control mode requests. This issue is resolved in NTP version 4.2.8p9. Various OS vendors like Red Hat and Ubuntu have also released patches for their respective distributions.

Affected products

  • NTP Project ntpd before 4.2.8p9
  • Red Hat Enterprise Linux 6
  • Red Hat Enterprise Linux 7

Timeline

  • 2016-11-21: advisory: Initial security notice by NTP project (Bug 3118)
  • 2017-01-13: disclosed: NVD publication date
  • 2017-02-06: patched: Red Hat released security updates (RHSA-2017:0252)

References

Related threats