Back

MEDIUM

ntp: receive() missing return on error

Published Dec 20, 2014

Description

The receive function in ntp_proto.c in ntpd in NTP before 4.2.8 continues to execute after detecting a certain authentication error, which might allow remote attackers to trigger an unintended association change via crafted packets.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of ntpd as shipped with Red Hat Enterprise Linux 4 and 5. It has been addressed in Red Hat Enterprise Linux 6 and 7 via RHSA-2014:2024.

Red Hat mitigation

Remove or comment out all configuration directives beginning with the crypto keyword in your ntp.conf file.

Metrics

Weaknesses (2)

References (24)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 20, 2014
Updated Aug 6, 2024
Reserved Dec 5, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Dec 19, 2014