PT-2020-2999 · Nts+7 · Ntp+7

Published

2020-03-24

·

Updated

2025-05-05

·

CVE-2020-11868

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions ntp versions 4.2.8 through 4.2.8p14 ntp versions 4.3.x through 4.3.100
Description The issue allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address. This is because transmissions are rescheduled even when a packet lacks a valid origin timestamp. The vulnerability is also related to an uncontrolled consumption of resources, which can be exploited by a remote attacker to cause a denial of service. Additionally, memory consumption can occur when sending packets due to memory not being freed in certain situations involving a CMAC key and algorithm in the ntp.keys file.
Recommendations For ntp versions 4.2.8 through 4.2.8p14, update to version 4.2.8p15 or later to resolve the issue. For ntp versions 4.3.x through 4.3.100, update to version 4.3.101 or later to resolve the issue. As a temporary workaround, consider restricting access to the ntpd service to minimize the risk of exploitation.

Fix

DoS

Resource Exhaustion

Origin Validation Error

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1552
ALT-PU-2020-1678
BDU:2020-03220
CESA-2020_2663
CVE-2020-11868
DLA-2201-1
MGASA-2020-0212
OPENSUSE-SU-2020:0934-1
OPENSUSE-SU-2020:1007-1
OPENSUSE-SU-2020_0934-1
OPENSUSE-SU-2020_1007-1
OPENSUSE-SU-2024:11102-1
RHSA-2020:2663
RHSA-2020_2663
SUSE-SU-2020:14415-1
SUSE-SU-2020:1805-1
SUSE-SU-2020:1823-1

Affected Products

Alt Linux
Astra Linux
Centos
Ibm Aix
Red Hat
Red Os
Suse
Ntp