Back

MEDIUM

ntp: certain remote configuration values not properly validated

Published Jan 30, 2017

Description

NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (prevent subsequent authentication) by leveraging knowledge of the controlkey or requestkey and sending a crafted packet to ntpd, which changes the value of trustedkey, controlkey, or requestkey. NOTE: this vulnerability exists because of a CVE-2016-2516 regression.

Affected products

Remediation

Red Hat statement

Red Hat Product Security does not consider this to be a security issue. An authenticated user could use various other means to disable access to an NTP server (for example, using the 'restrict' command). To mitigate this issue, disable remote configuration of NTP, or restrict this ability to trusted users.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 30, 2017
Updated Aug 5, 2024
Reserved Feb 20, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date Apr 26, 2016