Back

HIGH

ntp: Client rate limiting and server responses

Published Jan 13, 2017

Description

NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.

Affected products

Remediation

Red Hat mitigation

If you choose to use restrict default limited ..., be sure to use restrict source ... (without limited) to avoid this attack.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 13, 2017
Updated Aug 6, 2024
Reserved Sep 9, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 21, 2016