Back

MEDIUM

ntp: DoS via origin timestamp check functionality

Published Jun 4, 2018

Description

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

Affected products

Remediation

Red Hat mitigation

Implement BCP-38. Configure enough servers/peers that an attacker cannot target all of your time sources. Properly monitor your ntpd instances, and auto-restart ntpd (without -g) if it stops running.

Metrics

References (26)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner talos
Published Jun 4, 2018
Updated Sep 17, 2024
Reserved Oct 26, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 21, 2017