PT-2017-10048 · Ntf+7 · Ntp+7

Aanchal Malhotra

+3

·

Publicado

2016-12-08

·

Atualizado

2024-06-15

·

CVE-2016-9310

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions NTP versions prior to 4.2.8p9
Description The issue allows remote attackers to set or unset traps via a crafted control mode packet, which can lead to a denial of service caused by a NULL pointer dereference when the trap service has been enabled. By sending specially crafted packets, a remote attacker could exploit this to cause the application to crash.
Recommendations For versions prior to 4.2.8p9, update to version 4.2.8p9 or later to resolve the issue. As a temporary workaround, consider disabling the trap service to minimize the risk of exploitation. Restrict access to the control mode functionality to minimize the risk of exploitation.

Correção

DoS

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2335
CESA-2017_0252
CVE-2016-9310
MGASA-2016-0414
OPENSUSE-SU-2024:10181-1
RHSA-2017:0252
RHSA-2017_0252
SUSE-SU-2016:3193-1
SUSE-SU-2016:3195-1
SUSE-SU-2016:3196-1
SUSE-SU-2017:0255-1
USN-3349-1
USN-3707-2

Produtos afetados

Alt Linux
Centos
Freebsd
Ibm Aix
Ntp
Red Hat
Suse
Ubuntu