Back

HIGH

ntp: automatic generation of weak default key in config_auth()

Published Dec 20, 2014

Description

The config_auth function in ntpd in NTP before 4.2.7p11, when an auth key is not configured, improperly generates a key, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.

Affected products

Remediation

Red Hat mitigation

Issue these commands to explicitly generate a strong key and add it to the ntpd configuration: echo trustedkey 65535 >> /etc/ntp.conf printf "65535\tM\t%s\n" $(tr -cd a-zA-Z0-9 < /dev/urandom | head -c 16) >> /etc/ntp/keys The generated key has about 95 bits of entropy.

Metrics

Weaknesses (1)

References (26)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 20, 2014
Updated Aug 6, 2024
Reserved Dec 5, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 19, 2014