PT-2017-10048 · Ntf+7 · Ntp+7
Aanchal Malhotra
+3
·
Published
2016-12-08
·
Updated
2024-06-15
·
CVE-2016-9310
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
NTP versions prior to 4.2.8p9
Description
The issue allows remote attackers to set or unset traps via a crafted control mode packet, which can lead to a denial of service caused by a NULL pointer dereference when the trap service has been enabled. By sending specially crafted packets, a remote attacker could exploit this to cause the application to crash.
Recommendations
For versions prior to 4.2.8p9, update to version 4.2.8p9 or later to resolve the issue. As a temporary workaround, consider disabling the trap service to minimize the risk of exploitation. Restrict access to the control mode functionality to minimize the risk of exploitation.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Freebsd
Ibm Aix
Ntp
Red Hat
Suse
Ubuntu