Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-9042

Опубликовано: 04 июн. 2018
Источник: debian

Описание

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ntpfixed1:4.2.8p10+dfsg-1package
ntpnot-affectedjessiepackage
ntpnot-affectedwheezypackage

Примечания

  • http://www.talosintelligence.com/reports/TALOS-2016-0260/

  • http://support.ntp.org/bin/view/Main/NtpBug3361

  • This vulnerability affects the upstream fix for CVE-2015-8138, but Debian

  • jessie and wheezy use a less invasive patch by Miroslav Lichvar

  • of Red Hat, as available here:

  • http://pkgs.fedoraproject.org/cgit/rpms/ntp.git/tree/ntp-4.2.6p5-cve-2015-8138.patch?h=f24

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 7 лет назад

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

CVSS3: 5.9
redhat
почти 9 лет назад

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

CVSS3: 5.9
nvd
больше 7 лет назад

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

CVSS3: 5.9
github
больше 3 лет назад

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

suse-cvrf
почти 9 лет назад

Security update for ntp