Back

HIGH

ntp: multiple integer overflow read access violations

Published Jan 6, 2017

Description

An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a specially crafted private mode packet. The crafted packet needs to have the correct message authentication code and a valid timestamp. When processed by the NTP daemon, it leads to an immediate crash.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of ntp as shipped with Red Hat Enterprise Linux 5, 6, and 7, as they do not include the affected functionality.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 6, 2017
Updated Aug 6, 2024
Reserved Oct 16, 2015
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 21, 2015