Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4955

Опубликовано: 02 июн. 2016
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet with an incorrect MAC value at a certain time.

Меры по смягчению последствий

Disable autokey authentication. Instead, configure ntp to use symmetric key authentication, or no authentication at all (if not required). To configure ntp with symmetric key authentication, follow the steps at https://access.redhat.com/solutions/393663

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ntpWill not fix
Red Hat Enterprise Linux 6ntpWill not fix
Red Hat Enterprise Linux 7ntpWill not fix

Показывать по

Дополнительная информация

Статус:

Low

EPSS

Процентиль: 92%
0.0808
Низкий

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 9 лет назад

ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet with an incorrect MAC value at a certain time.

CVSS3: 5.9
nvd
больше 9 лет назад

ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet with an incorrect MAC value at a certain time.

CVSS3: 5.9
debian
больше 9 лет назад

ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote ...

CVSS3: 5.9
github
больше 3 лет назад

ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet with an incorrect MAC value at a certain time.

suse-cvrf
больше 9 лет назад

Security update for ntp

EPSS

Процентиль: 92%
0.0808
Низкий

2.6 Low

CVSS2