CVE-2015-5300
published 2017-07-21CVE-2015-5300: The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default…
PriorityP345high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
9.13%
94.7th percentile
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to an unspecified number of requests from trusted sources, and leveraging a resulting denial of service (abort and restart).
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ntp | < ntp 1:4.2.8p4+dfsg-2 (bullseye) | ntp 1:4.2.8p4+dfsg-2 (bullseye) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| ntp | ntp | <= 4.2.8 | — |
| ntp | ntp | >= 0 < 1:4.2.8p4+dfsg-2 | 1:4.2.8p4+dfsg-2 |
| ntp | ntp | >= 0 < 1:4.2.6.p5+dfsg-3ubuntu2.14.04.5 | 1:4.2.6.p5+dfsg-3ubuntu2.14.04.5 |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens RUGGEDCOM ROX-based Devices NTP Vulnerabilities
cisa_ics·2018-08-27
Siemens RUGGEDCOM ROX-based Devices NTP Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens RUGGEDCOM ROX-based Devices NTP Vulnerabilities
Last RevisedAugust 27, 2018
Alert CodeICSA-15-356-01
## OVERVIEW
Siemens has reported to NCCIC/ICS-CERT that NTP daemon vulnerabilities exist in the Siemens RUGGEDCOM ROX-based devices. Siemens has produced firmware updates to mitigate these vulnerabilities.
These vulnerabilities could be exploited remotely.
## AFFECTED PRODUCTS
The following Siemens RUGGEDCOM ROX versions are affected when NTP service is activated:
- ROX II: All versions prior to 2.9.0, and
- ROX I: All versions.
The NTP service is deactivated on ROX
BSD
FreeBSD-SA-16:02.ntp: ntp panic threshold bypass vulnerability
bsd_advisories·2016-01-14·CVSS 7.5
CVE-2015-5300 [HIGH] FreeBSD-SA-16:02.ntp: ntp panic threshold bypass vulnerability
FreeBSD-SA-16:02.ntp Security Advisory
The FreeBSD Project
Topic: ntp panic threshold bypass vulnerability
Category: contrib
Module: ntp
Announced: 2016-01-14
Credits: Network Time Foundation
Affects: All supported versions of FreeBSD.
Corrected: 2016-01-11 01:09:50 UTC (stable/10, 10.2-STABLE)
2016-01-14 09:10:46 UTC (releng/10.2, 10.2-RELEASE-p9)
2016-01-14 09:11:16 UTC (releng/10.1, 10.1-RELEASE-p26)
2016-01-11 01:48:16 UTC (stable/9, 9.3-STABLE)
2016-01-14 09:11:26 UTC (releng/9.3, 9.3-RELEASE-p33)
CVE Name: CVE-2015-5300
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
The ntpd(8) daemon is an implementation of the Network Time Protocol (NTP)
used
Ubuntu
NTP vulnerabilities
vendor_ubuntu·2015-10-27·CVSS 5.3
CVE-2015-5146 [MEDIUM] NTP vulnerabilities
Title: NTP vulnerabilities
Summary: Several security issues were fixed in NTP.
Aleksis Kauppinen discovered that NTP incorrectly handled certain remote
config packets. In a non-default configuration, a remote authenticated
attacker could possibly use this issue to cause NTP to crash, resulting in
a denial of service. (CVE-2015-5146)
Miroslav Lichvar discovered that NTP incorrectly handled logconfig
directives. In a non-default configuration, a remote authenticated attacker
could possibly use this issue to cause NTP to crash, resulting in a denial
of service. (CVE-2015-5194)
Miroslav Lichvar discovered that NTP incorrectly handled certain statistics
types. In a non-default configuration, a remote authenticated attacker
could possibly use this issue to cause NTP to crash, resulting in a
Red Hat
ntp: MITM attacker can force ntpd to make a step larger than the panic threshold
vendor_redhat·2015-10-21·CVSS 7.5
CVE-2015-5300 [HIGH] CWE-20 ntp: MITM attacker can force ntpd to make a step larger than the panic threshold
ntp: MITM attacker can force ntpd to make a step larger than the panic threshold
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to an unspecified number of requests from trusted sources, and leveraging a resulting denial of service (abort and restart).
It was found that ntpd did not correctly implement the threshold limitation for the '-g' option, which is used to set the time without any restrictions. A man-in-the-middle attacker able to intercept NTP traffic between a connecting client and an NTP server could use this fl
Debian
CVE-2015-5300: ntp - The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first ch...
vendor_debian·2015·CVSS 7.5
CVE-2015-5300 [HIGH] CVE-2015-5300: ntp - The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first ch...
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to an unspecified number of requests from trusted sources, and leveraging a resulting denial of service (abort and restart).
Scope: local
bullseye: resolved (fixed in 1:4.2.8p4+dfsg-2)
GHSA
GHSA-28h7-c4wm-4753: The panic_gate check in NTP before 4
ghsa_unreviewed·2022-05-14
CVE-2015-5300 [HIGH] GHSA-28h7-c4wm-4753: The panic_gate check in NTP before 4
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to an unspecified number of requests from trusted sources, and leveraging a resulting denial of service (abort and restart).
OSV
php7.2, php7.4 vulnerabilities
osv·2022-03-03·CVSS 6.5
CVE-2015-9253 php7.2, php7.4 vulnerabilities
php7.2, php7.4 vulnerabilities
USN-5300-1 fixed vulnerabilities in PHP. This update provides the
corresponding updates for Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that PHP incorrectly handled certain scripts.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2015-9253, CVE-2017-8923, CVE-2017-9118, CVE-2017-9120)
It was discovered that PHP incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service,
or possibly obtain sensitive information. (CVE-2017-9119)
It was discovered that PHP incorrectly handled certain scripts with XML
parsing functions.
An attacker could possibly use this issue to obtain sensitive information.
(CVE-2021-21707)
OSV
CVE-2015-5300: The panic_gate check in NTP before 4
osv·2017-07-21·CVSS 7.5
CVE-2015-5300 [HIGH] CVE-2015-5300: The panic_gate check in NTP before 4
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to an unspecified number of requests from trusted sources, and leveraging a resulting denial of service (abort and restart).
OSV
ntp vulnerabilities
osv·2015-10-27·CVSS 5.3
CVE-2015-5146 [MEDIUM] ntp vulnerabilities
ntp vulnerabilities
Aleksis Kauppinen discovered that NTP incorrectly handled certain remote
config packets. In a non-default configuration, a remote authenticated
attacker could possibly use this issue to cause NTP to crash, resulting in
a denial of service. (CVE-2015-5146)
Miroslav Lichvar discovered that NTP incorrectly handled logconfig
directives. In a non-default configuration, a remote authenticated attacker
could possibly use this issue to cause NTP to crash, resulting in a denial
of service. (CVE-2015-5194)
Miroslav Lichvar discovered that NTP incorrectly handled certain statistics
types. In a non-default configuration, a remote authenticated attacker
could possibly use this issue to cause NTP to crash, resulting in a denial
of service. (CVE-2015-5195)
Miroslav Lichvar discove
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7704 CVE-2015-5300 ntp: two flaws [fedora-all]
bugzilla·2015-10-22·CVSS 7.5
CVE-2015-7704 [HIGH] CVE-2015-7704 CVE-2015-5300 ntp: two flaws [fedora-all]
CVE-2015-7704 CVE-2015-5300 ntp: two flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
one
Bugzilla
CVE-2015-5300 ntp: MITM attacker can force ntpd to make a step larger than the panic threshold [fedora-all]
bugzilla·2015-10-22·CVSS 7.5
CVE-2015-5300 [HIGH] CVE-2015-5300 ntp: MITM attacker can force ntpd to make a step larger than the panic threshold [fedora-all]
CVE-2015-5300 ntp: MITM attacker can force ntpd to make a step larger than the panic threshold [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
Bugzilla
CVE-2015-5300 ntp: MITM attacker can force ntpd to make a step larger than the panic threshold
bugzilla·2015-10-13·CVSS 7.5
CVE-2015-5300 [HIGH] CVE-2015-5300 ntp: MITM attacker can force ntpd to make a step larger than the panic threshold
CVE-2015-5300 ntp: MITM attacker can force ntpd to make a step larger than the panic threshold
It was found that ntpd did not correctly implement the -g option:
-g Normally, ntpd exits with a message to the system log if the offset exceeds the panic threshold, which is 1000 s by default. This option allows the time to be set to any value without restriction; however, this can happen only once. If the thresh‐ old is exceeded after that, ntpd will exit with a message to the system log. This option can be used with the -q and -x options. See the tinker command for other options.
ntpd could actually step the clock multiple times by more than the panic threshold if its clock discipline doesn't have enough time to reach the sync state and stay there for at least one update. If a man-in-the-mi
arXiv
Preventing Time Synchronization in NTP's Broadcast Mode
arxiv_fulltext·2020-05-14
Preventing Time Synchronization in NTP's Broadcast Mode
Preventing Time Synchronization in NTP's Broadcast Mode
Nikhil Tripathi1,
Neminath Hubballi2
Nikhil Tripathi is with Technical University of Darmstadt, Rheinstr. 75, 64295 Darmstadt, Germany. Neminath Hubballi is with Discipline of Computer Science and Engineering, Indian Institute of Technology Indore, India. (E-mails:[email protected], [email protected]). 1Corresponding Author
## Abstract
Network Time Protocol (NTP) is used by millions of hosts in Internet today to synchronize their clocks. Clock synchronization is necessary for many network applications to function correctly. Unsynchronized clock may lead to failure of various core Internet services including DNS and RPKI based interdomain routing and opens path for more sophisticated attacks. In this paper
http://aix.software.ibm.com/aix/efixes/security/ntp_advisory5.aschttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/170684.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/170926.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/177507.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00059.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00060.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00038.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00048.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00042.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00114.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1930.htmlhttp://seclists.org/bugtraq/2016/Feb/164http://support.ntp.org/bin/view/Main/NtpBug2956http://support.ntp.org/bin/view/Main/SecurityNotice#January_2016_NTP_4_2_8p5_Securithttp://www.debian.org/security/2015/dsa-3388http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.securityfocus.com/bid/77312http://www.securitytracker.com/id/1034670http://www.ubuntu.com/usn/USN-2783-1https://bto.bluecoat.com/security-advisory/sa113https://bugzilla.redhat.com/show_bug.cgi?id=1271076https://ics-cert.us-cert.gov/advisories/ICSA-15-356-01https://security.netapp.com/advisory/ntap-20171004-0001/https://support.citrix.com/article/CTX220112https://www-01.ibm.com/support/docview.wss?uid=isg3T1023885https://www-01.ibm.com/support/docview.wss?uid=isg3T1024073https://www-01.ibm.com/support/docview.wss?uid=nas8N1021264https://www-01.ibm.com/support/docview.wss?uid=ssg1S1005821https://www-01.ibm.com/support/docview.wss?uid=swg21979393https://www-01.ibm.com/support/docview.wss?uid=swg21980676https://www-01.ibm.com/support/docview.wss?uid=swg21983501https://www-01.ibm.com/support/docview.wss?uid=swg21983506https://www.cs.bu.edu/~goldbe/NTPattack.htmlhttps://www.freebsd.org/security/advisories/FreeBSD-SA-16:02.ntp.aschttps://www.ibm.com/support/home/docdisplay?lndocid=migr-5099428https://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttps://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://aix.software.ibm.com/aix/efixes/security/ntp_advisory5.aschttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/170684.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/170926.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/177507.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00059.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00060.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00038.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00048.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00042.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00114.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1930.htmlhttp://seclists.org/bugtraq/2016/Feb/164http://support.ntp.org/bin/view/Main/NtpBug2956http://support.ntp.org/bin/view/Main/SecurityNotice#January_2016_NTP_4_2_8p5_Securithttp://www.debian.org/security/2015/dsa-3388http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.securityfocus.com/bid/77312http://www.securitytracker.com/id/1034670http://www.ubuntu.com/usn/USN-2783-1https://bto.bluecoat.com/security-advisory/sa113https://bugzilla.redhat.com/show_bug.cgi?id=1271076https://ics-cert.us-cert.gov/advisories/ICSA-15-356-01https://security.netapp.com/advisory/ntap-20171004-0001/https://support.citrix.com/article/CTX220112https://www-01.ibm.com/support/docview.wss?uid=isg3T1023885https://www-01.ibm.com/support/docview.wss?uid=isg3T1024073https://www-01.ibm.com/support/docview.wss?uid=nas8N1021264https://www-01.ibm.com/support/docview.wss?uid=ssg1S1005821https://www-01.ibm.com/support/docview.wss?uid=swg21979393https://www-01.ibm.com/support/docview.wss?uid=swg21980676https://www-01.ibm.com/support/docview.wss?uid=swg21983501https://www-01.ibm.com/support/docview.wss?uid=swg21983506https://www.cs.bu.edu/~goldbe/NTPattack.htmlhttps://www.freebsd.org/security/advisories/FreeBSD-SA-16:02.ntp.aschttps://www.ibm.com/support/home/docdisplay?lndocid=migr-5099428https://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttps://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
2017-07-21
Published