Back

MEDIUM

ntp: broadcast interleave (incomplete fix for CVE-2016-1548)

Published Jul 5, 2016

Description

ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-1548.

Affected products

Remediation

Red Hat mitigation

Do not use NTP's broadcast mode in the clients by not configuring the "broadcastclient" directive in the ntp.conf file.

Metrics

Weaknesses (0)

No CWE recorded.

References (38)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 5, 2016
Updated Aug 6, 2024
Reserved May 23, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jun 2, 2016