PT-2015-5445 · Ntt+8 · Ntp+10
Miroslav Lichvar
·
Published
2014-12-24
·
Updated
2024-06-15
·
CVE-2015-1799
CVSS v2.0
4.3
Medium
| Vector | AV:A/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
NTP versions 3.x through 4.2.8p1
NTP version 4.2.8p2 is not affected, as it is the fixed version, so all versions prior to 4.2.8p2 are vulnerable.
Description
The issue allows man-in-the-middle attackers to cause a denial of service, specifically synchronization loss, by spoofing the source IP address of a peer. This is due to the symmetric-key feature in the receive function performing state-variable updates upon receiving certain invalid packets. An attacker could exploit this by sending specially-crafted packets to both peering hosts, preventing synchronization.
Recommendations
For NTP versions 3.x through 4.2.8p1, update to version 4.2.8p2 or later to resolve the issue.
As a temporary workaround, consider restricting access to the symmetric key authentication feature until a patch is available.
Avoid using symmetric key authentication in the affected API endpoint until the issue is resolved.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Cisco Ios Xe
Cisco Ios Xr
Cisco Nexus
Hp-Ux
Ibm Aix
Ntp
Red Hat
Suse
Ubuntu