PT-2015-5445 · Ntt+8 · Ntp+10

Miroslav Lichvar

·

Publicado

2014-12-24

·

Atualizado

2024-06-15

·

CVE-2015-1799

CVSS v2.0

4.3

Média

VetorAV:A/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions NTP versions 3.x through 4.2.8p1 NTP version 4.2.8p2 is not affected, as it is the fixed version, so all versions prior to 4.2.8p2 are vulnerable.
Description The issue allows man-in-the-middle attackers to cause a denial of service, specifically synchronization loss, by spoofing the source IP address of a peer. This is due to the symmetric-key feature in the receive function performing state-variable updates upon receiving certain invalid packets. An attacker could exploit this by sending specially-crafted packets to both peering hosts, preventing synchronization.
Recommendations For NTP versions 3.x through 4.2.8p1, update to version 4.2.8p2 or later to resolve the issue. As a temporary workaround, consider restricting access to the symmetric key authentication feature until a patch is available. Avoid using symmetric key authentication in the affected API endpoint until the issue is resolved.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-2486
CESA-2015_1459
CESA-2015_2231
CVE-2015-1799
DLA-192-1
DSA-3223-1
HPSBUX03333
MGASA-2015-0152
OPENSUSE-SU-2024:10181-1
RHSA-2015:1459
RHSA-2015:2231
RHSA-2015_1459
RHSA-2015_2231
SUSE-SU-2015:0259-1
SUSE-SU-2015:0259-3
SUSE-SU-2015:0865-1
SUSE-SU-2015:1173-1
SUSE-SU-2015_1173-1
USN-2567-1

Produtos afetados

Alt Linux
Centos
Cisco Ios Xe
Cisco Ios Xr
Cisco Nexus
Hp-Ux
Ibm Aix
Ntp
Red Hat
Suse
Ubuntu