Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-9042

Опубликовано: 04 июн. 2018
Источник: debian
EPSS Низкий

Описание

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ntpfixed1:4.2.8p10+dfsg-1package
ntpnot-affectedjessiepackage
ntpnot-affectedwheezypackage

Примечания

  • http://www.talosintelligence.com/reports/TALOS-2016-0260/

  • http://support.ntp.org/bin/view/Main/NtpBug3361

  • This vulnerability affects the upstream fix for CVE-2015-8138, but Debian

  • jessie and wheezy use a less invasive patch by Miroslav Lichvar

  • of Red Hat, as available here:

  • http://pkgs.fedoraproject.org/cgit/rpms/ntp.git/tree/ntp-4.2.6p5-cve-2015-8138.patch?h=f24

EPSS

Процентиль: 89%
0.0391
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 8 лет назад

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

CVSS3: 5.9
redhat
больше 9 лет назад

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

CVSS3: 5.9
nvd
около 8 лет назад

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

CVSS3: 5.9
github
больше 4 лет назад

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

suse-cvrf
больше 9 лет назад

Security update for ntp

EPSS

Процентиль: 89%
0.0391
Низкий