Back

MEDIUM

ntp: Information Disclosure vulnerability via GET_RESTRICT control message

Published Jan 8, 2020

Description

An Information Disclosure vulnerability exists in NTP 4.2.7p25 private (mode 6/7) messages via a GET_RESTRICT control message, which could let a malicious user obtain sensitive information.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of ntp as shipped with Red Hat Enterprise Linux 5, 6, 7 in their default configurations. Red Hat Enterprise Linux uses the `restrict noquery` option by default, which denies ntpdc queries. No proper fix is available for this issue upstream, apart from disabling these kind of queries by default or denying them through the `restrict` access control command specified in /etc/ntp.conf. Users are adviced to use `noquery` in their configurations and allow them only from a trusted set of network addresses.

Red Hat mitigation

If not already present, add `noquery` option to the `restrict` access control command specified in /etc/ntp.conf. Red Hat Enterprise Linux 7 is shipped by default with the following setting: restrict default nomodify notrap nopeer noquery

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published Jan 8, 2020
Updated Aug 6, 2024
Reserved Aug 13, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Aug 25, 2014