Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-1550

Опубликовано: 26 апр. 2016
Источник: redhat
CVSS2: 2.6

Описание

An exploitable vulnerability exists in the message authentication functionality of libntp in ntp 4.2.8p4 and NTPSec a5fb34b9cc89b92a8fef2f459004865c93bb7f92. An attacker can send a series of crafted messages to attempt to recover the message digest key.

A flaw was found in the way NTP's libntp performed message authentication. An attacker able to observe the timing of the comparison function used in packet authentication could potentially use this flaw to recover the message digest.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ntpWill not fix
Red Hat Enterprise Linux 6ntpFixedRHSA-2016:114131.05.2016
Red Hat Enterprise Linux 6.7 Extended Update SupportntpFixedRHSA-2016:155203.08.2016
Red Hat Enterprise Linux 7ntpFixedRHSA-2016:114131.05.2016

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1331464ntp: libntp message digest disclosure

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 8 лет назад

An exploitable vulnerability exists in the message authentication functionality of libntp in ntp 4.2.8p4 and NTPSec a5fb34b9cc89b92a8fef2f459004865c93bb7f92. An attacker can send a series of crafted messages to attempt to recover the message digest key.

CVSS3: 5.3
nvd
больше 8 лет назад

An exploitable vulnerability exists in the message authentication functionality of libntp in ntp 4.2.8p4 and NTPSec a5fb34b9cc89b92a8fef2f459004865c93bb7f92. An attacker can send a series of crafted messages to attempt to recover the message digest key.

CVSS3: 5.3
debian
больше 8 лет назад

An exploitable vulnerability exists in the message authentication func ...

CVSS3: 5.3
github
больше 3 лет назад

An exploitable vulnerability exists in the message authentication functionality of libntp in ntp 4.2.8p4 and NTPSec a5fb34b9cc89b92a8fef2f459004865c93bb7f92. An attacker can send a series of crafted messages to attempt to recover the message digest key.

oracle-oval
около 9 лет назад

ELSA-2016-1141: ntp security update (MODERATE)

2.6 Low

CVSS2