Back

MEDIUM

ntp: assertion failure in ntpd on duplicate IPs on unconfig directives

Published Jan 30, 2017

Description

NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote attackers to cause a denial of service (ntpd abort) by using the same IP address multiple times in an unconfig directive.

Affected products

Remediation

Red Hat mitigation

Disable remote configuration of NTP, or restrict this ability to trusted users.

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 30, 2017
Updated Aug 5, 2024
Reserved Feb 20, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 26, 2016