Back

HIGH

ntp: bad authentication demobilizes ephemeral associations

Published Jul 5, 2016

Description

ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of ntp as shipped with any Red Hat Enterprise Linux version as they already included a fix for this issue in the patch provided to fix the CVE-2015-7979 issue. The fix for this issue (developed by Red Hat) was different from the one provided by upstream, and thus ntp versions in RHEL are not affected by CVE-2016-4953.

Metrics

References (37)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 5, 2016
Updated Aug 6, 2024
Reserved May 23, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jun 2, 2016