ntp: ntpd allows remote attackers to prevent a broadcast client from synchronizing its clock
Published May 6, 2020
5.3
MEDIUMCVSS 3.1
EPSS 3.14%
Description
ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via soofed mode 3 and mode 5 packets. The attacker must either be a part of the same broadcast network or control a slave in that broadcast network that can capture certain required packets on the attacker's behalf and send them to the attacker.
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
ntp
Not affected
Red Hat Enterprise Linux 6
ntp
Not affected
Red Hat Enterprise Linux 7
ntp
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | ntp | Not affected | n/a |
| Red Hat Enterprise Linux 6 | ntp | Not affected | n/a |
| Red Hat Enterprise Linux 7 | ntp | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
As per the researcher this issue only affects NTP versions 4.2.8p10 through 4.2.8p13, which are not shipped with any Red Hat products, therefore they are not affected by this flaw.
References (12)
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00005.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00044.html vendor-advisoryx_refsource_SUSE
- http://www.ntp.org/ x_refsource_MISCVendor Advisory
- https://access.redhat.com/security/cve/CVE-2018-8956 Vendor Advisory
- https://arxiv.org/abs/2005.01783 x_refsource_MISCThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1848589 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-20563 Advisory
- https://nikhiltripathi.in/NTP_attack.pdf x_refsource_MISCThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-8956
- https://security.netapp.com/advisory/ntap-20200518-0006/ x_refsource_CONFIRM
- https://tools.ietf.org/html/rfc5905 x_refsource_MISCThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-8956
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00005.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00044.html | vendor-advisoryx_refsource_SUSE | |
| http://www.ntp.org/ | x_refsource_MISCVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2018-8956 | Vendor Advisory | |
| https://arxiv.org/abs/2005.01783 | x_refsource_MISCThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1848589 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-20563 | Advisory | |
| https://nikhiltripathi.in/NTP_attack.pdf | x_refsource_MISCThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-8956 | ||
| https://security.netapp.com/advisory/ntap-20200518-0006/ | x_refsource_CONFIRM | |
| https://tools.ietf.org/html/rfc5905 | x_refsource_MISCThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2018-8956 |
Change history (0)
No recorded changes yet.