Junglewise Threat Intelligence

CVE-2016-9311: NTP Project ntpd denial of service in trap service

CVE-2016-9311 · Severity: medium · CVSS 5.9 · Published 2017-01-13

Executive brief

A vulnerability in the Network Time Protocol (NTP) service could allow a remote attacker to crash the system's time-synchronization daemon. This service is critical for ensuring all computers on a network share the same accurate time for logging and security purposes. An exploit would result in a denial of service, potentially causing issues with time-sensitive applications and security protocols.

Technical details

A NULL pointer dereference vulnerability exists in the trap service implementation of ntpd. When the trap service is enabled, a remote, unauthenticated attacker can send a specially crafted packet to trigger the dereference, causing the ntpd process to crash. This vulnerability is exploited via the network and requires the trap service to be active, which is not the default configuration in all environments. The issue is resolved in NTP version 4.2.8p9.

Affected products

  • NTP Project ntpd before 4.2.8p9
  • Red Hat Enterprise Linux 6, 7

Timeline

  • 2016-11-21: disclosed: Initial public disclosure via NTP project bug 3119
  • 2016-11-21: patched: Fixed in NTP 4.2.8p9
  • 2017-01-13: advisory: NVD publication date

References

Related threats