CVE-2015-1798
published 2015-04-08CVE-2015-1798: The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p2 requires a correct MAC only if the MAC field has a nonzero…
PriorityP413low1.8CVSS 2.0
AVAACHAuNCNIPAN
EPSS
2.22%
80.8th percentile
The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p2 requires a correct MAC only if the MAC field has a nonzero length, which makes it easier for man-in-the-middle attackers to spoof packets by omitting the MAC.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_yosemite_v10.10.4_and_security_update_2015-005 | — | — |
| cisco | products | — | — |
| debian | ntp | < ntp 1:4.2.6.p5+dfsg-6 (bullseye) | ntp 1:4.2.6.p5+dfsg-6 (bullseye) |
| ntp | ntp | <= 4.2.7p444 | — |
| ntp | ntp | >= 0 < 1:4.2.6.p5+dfsg-6 | 1:4.2.6.p5+dfsg-6 |
| ntp | ntp | >= 0 < 1:4.2.6.p5+dfsg-3ubuntu2.14.04.3 | 1:4.2.6.p5+dfsg-3ubuntu2.14.04.3 |
CVSS provenance
nvdv2.01.8LOWAV:A/AC:H/Au:N/C:N/I:P/A:N
osv1.8LOW
vendor_cisco1.8LOW
vendor_debian1.8LOW
vendor_redhat1.8LOW
vendor_ubuntu1.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation Stratix 5900
cisa_ics·2017-05-10
Rockwell Automation Stratix 5900
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix 5900
Last RevisedMay 10, 2017
Alert CodeICSA-17-094-04
## CVSS v3 10.0
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Rockwell Automation
Equipment: Stratix 5900
Vulnerabilities: Improper Input Validation, Resource Management Errors, Improper Authentication, Path Traversal.
## REPOSTED INFORMATION
This advisory was originally posted to the NCCIC Portal on April 4, 2017, and is being released to the NCCIC/ICS-CERT web site.
## AFFECTED PRODUCTS
Rockwell Automation reports that these vulnerabilities affect the following Strat
Ubuntu
NTP vulnerabilities
vendor_ubuntu·2015-04-13·CVSS 1.8
CVE-2015-1798 [LOW] NTP vulnerabilities
Title: NTP vulnerabilities
Summary: Several security issues were fixed in NTP.
Miroslav Lichvar discovered that NTP incorrectly validated MAC fields. A
remote attacker could possibly use this issue to bypass authentication and
spoof packets. (CVE-2015-1798)
Miroslav Lichvar discovered that NTP incorrectly handled certain invalid
packets. A remote attacker could possibly use this issue to cause a denial
of service. (CVE-2015-1799)
Juergen Perlinger discovered that NTP incorrectly generated MD5 keys on
big-endian platforms. This issue could either cause ntp-keygen to hang, or
could result in non-random keys. (CVE number pending)
Instructions: In general, a standard system update will make all the necessary changes.
Cisco
Network Time Protocol Daemon MAC Checking Failure Authentication Bypass Vulnerability
vendor_cisco·2015-04-09·CVSS 1.8
CVE-2015-1798 [LOW] CWE-264 Network Time Protocol Daemon MAC Checking Failure Authentication Bypass Vulnerability
Network Time Protocol Daemon MAC Checking Failure Authentication Bypass Vulnerability
A vulnerability in the Network Time Protocol (NTP) daemon could allow an unauthenticated, adjacent attacker to bypass authentication mechanisms and access an affected system.
The vulnerability is due to incorrect validation of the message authentication code (MAC) field. An attacker could exploit this vulnerability by sending unauthenticated NTP packets to an NTP host that is configured with symmetric key authentication. An exploit could allow the attacker to inject NTP packets to the NTP host without knowing the NTP symmetric key.
NTP.org has released a security notice and software updates to address the vulnerability.
To exploit the vulnerability, the attacker may need access to trusted or internal
Cisco
Multiple Vulnerabilities in ntpd (April 2015) Affecting Cisco Products
vendor_cisco·2015-04-08·CVSS 1.8
CVE-2015-1798 [LOW] CWE-287 Multiple Vulnerabilities in ntpd (April 2015) Affecting Cisco Products
Multiple Vulnerabilities in ntpd (April 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the ntpd package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to bypass authentication controls or to create a denial of service (DoS) condition.
On April 7, 2015, NTP.org and US-CERT released a security advisory dealing with two issues regarding bypass of authentication controls. These vulnerabilities are referenced in this document as follows:
CVE-2015-1798: NTP Authentication bypass vulnerability
CVE-2015-1799: NTP Authentication doesn't protect symmetric associations against DoS attacks
Cisco has released software updates that address these vulnerabilities.
Workarounds that mitigate the
BSD
FreeBSD-SA-15:07.ntp: Multiple vulnerabilities of ntp
bsd_advisories·2015-04-07·CVSS 1.8
CVE-2014-9297 [LOW] FreeBSD-SA-15:07.ntp: Multiple vulnerabilities of ntp
FreeBSD-SA-15:07.ntp Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities of ntp
Category: contrib
Module: ntp
Announced: 2015-04-07
Credits: Network Time Foundation
Affects: All supported versions of FreeBSD.
Corrected: 2015-04-07 20:20:24 UTC (stable/10, 10.1-STABLE)
2015-04-07 20:21:01 UTC (releng/10.1, 10.1-RELEASE-p9)
2015-04-07 20:20:44 UTC (stable/9, 9.3-STABLE)
2015-04-07 20:21:23 UTC (releng/9.3, 9.3-RELEASE-p13)
2015-04-07 20:20:44 UTC (stable/8, 8.4-STABLE)
2015-04-07 20:21:23 UTC (releng/8.4, 8.4-RELEASE-p27)
CVE Name: CVE-2014-9297, CVE-2015-1798, CVE-2015-1799
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
The ntpd(8) da
Red Hat
ntp: ntpd accepts unauthenticated packets with symmetric key crypto
vendor_redhat·2015-04-07·CVSS 1.8
CVE-2015-1798 [LOW] CWE-347 ntp: ntpd accepts unauthenticated packets with symmetric key crypto
ntp: ntpd accepts unauthenticated packets with symmetric key crypto
The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p2 requires a correct MAC only if the MAC field has a nonzero length, which makes it easier for man-in-the-middle attackers to spoof packets by omitting the MAC.
It was found that ntpd did not check whether a Message Authentication Code (MAC) was present in a received packet when ntpd was configured to use symmetric cryptographic keys. A man-in-the-middle attacker could use this flaw to send crafted packets that would be accepted by a client or a peer without the attacker knowing the symmetric key.
Statement: This issue did not affect the version of ntp as shipped with Red Hat Enterprise Linux 5
Package: ntp (Red Hat Enterpr
Debian
CVE-2015-1798: ntp - The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP ...
vendor_debian·2015·CVSS 1.8
CVE-2015-1798 [LOW] CVE-2015-1798: ntp - The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP ...
The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p2 requires a correct MAC only if the MAC field has a nonzero length, which makes it easier for man-in-the-middle attackers to spoof packets by omitting the MAC.
Scope: local
bullseye: resolved (fixed in 1:4.2.6.p5+dfsg-6)
Apple
CVE-2015-1798: OS X Yosemite v10.10.4 and Security Update 2015-005
vendor_apple·CVSS 1.8
CVE-2015-1798 [LOW] CVE-2015-1798: OS X Yosemite v10.10.4 and Security Update 2015-005
Apple Security Update: About the security content of OS X Yosemite v10.10.4 and Security Update 2015-005
Product: OS X Yosemite v10.10.4 and Security Update 2015-005
CVE: CVE-2015-1798
Component: CVE-2015-1798
Cisco
Multiple Vulnerabilities in ntpd (April 2015) Affecting Cisco Products
vendor_cisco
CVE-2015-1799 Multiple Vulnerabilities in ntpd (April 2015) Affecting Cisco Products
CVE-2015-1799: Multiple Vulnerabilities in ntpd (April 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the ntpd package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to bypass authentication controls or to create a denial of service (DoS) condition. On April 7, 2015, NTP.org and US-CERT released a security advisory dealing with two issues regarding bypass of authentication controls. These vulnerabilities are referenced in this document as follows: CVE-2015-1798: NTP Authentication bypass vulnerability CVE-2015-1799: NTP Authentication doesn't protect symmetric associations against DoS attacks Cisco has released software updates that address these vulnerabilities.
CWE: CWE-287, CWE-2
Cisco
Multiple Vulnerabilities in ntpd (April 2015) Affecting Cisco Products
vendor_cisco
CVE-2015-1798 Multiple Vulnerabilities in ntpd (April 2015) Affecting Cisco Products
CVE-2015-1798: Multiple Vulnerabilities in ntpd (April 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the ntpd package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to bypass authentication controls or to create a denial of service (DoS) condition. On April 7, 2015, NTP.org and US-CERT released a security advisory dealing with two issues regarding bypass of authentication controls. These vulnerabilities are referenced in this document as follows: CVE-2015-1798: NTP Authentication bypass vulnerability CVE-2015-1799: NTP Authentication doesn't protect symmetric associations against DoS attacks Cisco has released software updates that address these vulnerabilities.
CWE: CWE-287, CWE-2
GHSA
GHSA-cx2f-jc4r-m5vp: The symmetric-key feature in the receive function in ntp_proto
ghsa_unreviewed·2022-05-14
CVE-2015-1798 [LOW] GHSA-cx2f-jc4r-m5vp: The symmetric-key feature in the receive function in ntp_proto
The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p2 requires a correct MAC only if the MAC field has a nonzero length, which makes it easier for man-in-the-middle attackers to spoof packets by omitting the MAC.
OSV
ntp vulnerabilities
osv·2015-04-13·CVSS 1.8
CVE-2015-1798 [LOW] ntp vulnerabilities
ntp vulnerabilities
Miroslav Lichvar discovered that NTP incorrectly validated MAC fields. A
remote attacker could possibly use this issue to bypass authentication and
spoof packets. (CVE-2015-1798)
Miroslav Lichvar discovered that NTP incorrectly handled certain invalid
packets. A remote attacker could possibly use this issue to cause a denial
of service. (CVE-2015-1799)
Juergen Perlinger discovered that NTP incorrectly generated MD5 keys on
big-endian platforms. This issue could either cause ntp-keygen to hang, or
could result in non-random keys. (CVE number pending)
OSV
CVE-2015-1798: The symmetric-key feature in the receive function in ntp_proto
osv·2015-04-08·CVSS 1.8
CVE-2015-1798 [LOW] CVE-2015-1798: The symmetric-key feature in the receive function in ntp_proto
The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p2 requires a correct MAC only if the MAC field has a nonzero length, which makes it easier for man-in-the-middle attackers to spoof packets by omitting the MAC.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8106 latex2rtf: Format string vulnerability in CmdKeywords
bugzilla·2015-11-16·CVSS 7.8
CVE-2015-8106 [HIGH] CVE-2015-8106 latex2rtf: Format string vulnerability in CmdKeywords
CVE-2015-8106 latex2rtf: Format string vulnerability in CmdKeywords
A format string vulnerability was found in CmdKeywords function when processing \keywords command in tex file. When the user runs latex2rtf with malicious crafted tex file, an attacker can execute arbitrary code. The variable `keywords' in the function CmdKeywords may hold a malicious input string, which can be used as a format argument of vsnprintf.
Vulnerable code:
1789 char *keywords = getBraceParam();
...
1798 fprintRTF(keywords);
...
858 void fprintRTF(char *format, ...){
...
873 vsnprintf(buffer, 1024, format, apf);
...
Public disclosure (includes reproducer and suggested fix):
http://seclists.org/oss-sec/2015/q4/283
Discussion:
Created latex2rtf tracking bugs for this issue:
Affects: fedora-all [bug 1282493
Bugzilla
CVE-2015-1798 CVE-2015-1799 ntp: various flaws [fedora-all]
bugzilla·2015-04-07·CVSS 1.8
CVE-2015-1798 [LOW] CVE-2015-1798 CVE-2015-1799 ntp: various flaws [fedora-all]
CVE-2015-1798 CVE-2015-1799 ntp: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
Bugzilla
CVE-2015-1798 ntp: ntpd accepts unauthenticated packets with symmetric key crypto
bugzilla·2015-03-06·CVSS 1.8
CVE-2015-1798 [LOW] CVE-2015-1798 ntp: ntpd accepts unauthenticated packets with symmetric key crypto
CVE-2015-1798 ntp: ntpd accepts unauthenticated packets with symmetric key crypto
When ntpd is configured to use a symmetric key with an NTP server/peer, it checks if the NTP message authentication code (MAC) in received packets is valid, but not if there actually is any MAC included. Packets without MAC are accepted as if they had a valid MAC. This allows a MITM attacker to send false packets that are accepted by the client/peer without having to know the symmetric key.
It seems this bug was introduced in 4.2.5p99 and is in all later stable versions up to 4.2.8p1. Authentication using autokey doesn't have this problem as there is a check that requires the key ID to be larger than NTP_MAXKEY, which fails for packets without MAC.
Discussion:
Acknowledgements:
This issue was discovered
http://bugs.ntp.org/show_bug.cgi?id=2779http://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155863.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155864.htmlhttp://lists.opensuse.org/opensuse-updates/2015-04/msg00052.htmlhttp://marc.info/?l=bugtraq&m=143213867103400&w=2http://rhn.redhat.com/errata/RHSA-2015-1459.htmlhttp://support.apple.com/kb/HT204942http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_Vulnerabilitieshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150408-ntpdhttp://tools.cisco.com/security/center/viewAlert.x?alertId=38276http://www.debian.org/security/2015/dsa-3223http://www.kb.cert.org/vuls/id/374268http://www.mandriva.com/security/advisories?name=MDVSA-2015:202http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/73951http://www.securitytracker.com/id/1032032http://www.ubuntu.com/usn/USN-2567-1https://kc.mcafee.com/corporate/index?page=content&id=SB10114https://security.gentoo.org/glsa/201509-01http://bugs.ntp.org/show_bug.cgi?id=2779http://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155863.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155864.htmlhttp://lists.opensuse.org/opensuse-updates/2015-04/msg00052.htmlhttp://marc.info/?l=bugtraq&m=143213867103400&w=2http://rhn.redhat.com/errata/RHSA-2015-1459.htmlhttp://support.apple.com/kb/HT204942http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_Vulnerabilitieshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150408-ntpdhttp://tools.cisco.com/security/center/viewAlert.x?alertId=38276http://www.debian.org/security/2015/dsa-3223http://www.kb.cert.org/vuls/id/374268http://www.mandriva.com/security/advisories?name=MDVSA-2015:202http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/73951http://www.securitytracker.com/id/1032032http://www.ubuntu.com/usn/USN-2567-1https://kc.mcafee.com/corporate/index?page=content&id=SB10114https://security.gentoo.org/glsa/201509-01
2015-04-08
Published