PT-2016-6189 · Ntf+5 · Ntp+5

Miroslav Lichvar

·

Publicado

2016-06-03

·

Atualizado

2024-06-15

·

CVE-2016-4956

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions NTP versions prior to 4.2.8p8
Description The issue allows remote attackers to cause a denial of service or modify the time being advertised by a device acting as a Network Time Protocol server via a spoofed broadcast packet. This is due to an incomplete fix for a previous issue. Multiple vulnerabilities exist, including Network Time Protocol CRYPTO-NAK Denial of Service, Network Time Protocol Bad Authentication, Network Time Protocol Processing Spoofed Server Packets, Network Time Protocol Autokey Association Reset, and Network Time Protocol Broadcast Interleave.
Recommendations For versions prior to 4.2.8p8, update to version 4.2.8p8 or later to resolve the issue. As a temporary workaround, consider restricting access to the ntpd package to minimize the risk of exploitation. Additionally, workarounds may be available and documented in the Cisco bug for each affected product.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

ALT-PU-2017-2335
CVE-2016-4956
MGASA-2016-0219
OPENSUSE-SU-2016_1583-1
OPENSUSE-SU-2016_1636-1
OPENSUSE-SU-2024:10181-1
SUSE-SU-2016:1563-1
SUSE-SU-2016:1568-1
SUSE-SU-2016:1584-1
SUSE-SU-2016:1602-1
USN-3096-1

Produtos afetados

Alt Linux
Cisco Ios
Freebsd
Ntp
Suse
Ubuntu