CVE-2016-1548
published 2017-01-06CVE-2016-1548: An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timestamp recorded for that server. After…
PriorityP342high7.2CVSS 3.0
AVNACLPRNUINSCCNILAL
EPSS
3.84%
89.0th percentile
An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timestamp recorded for that server. After making this switch, the client in NTP 4.2.8p4 and earlier and NTPSec aa48d001683e5b791a743ec9c575aaf7d867a2b0c will reject all future legitimate server responses. It is possible to force the victim client to move time after the mode has been changed. ntpq gives no indication that the mode has been switched.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ntp | < ntp 1:4.2.8p8+dfsg-1 (bullseye) | ntp 1:4.2.8p8+dfsg-1 (bullseye) |
| debian | ntp | < ntp 1:4.2.8p7+dfsg-1 (bullseye) | ntp 1:4.2.8p7+dfsg-1 (bullseye) |
| novell | suse_manager | — | — |
| ntp | ntp | — | — |
| ntp | ntp | >= 0 < 1:4.2.8p8+dfsg-1 | 1:4.2.8p8+dfsg-1 |
| ntp | ntp | >= 0 < 1:4.2.8p7+dfsg-1 | 1:4.2.8p7+dfsg-1 |
| ntp | ntp | >= 0 < 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 | 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 |
| ntp | ntp | >= 0 < 1:4.2.8p4+dfsg-3ubuntu5.3 | 1:4.2.8p4+dfsg-3ubuntu5.3 |
| ntp | ntp | >= 4.2.0 < 4.2.8 | 4.2.8 |
| ntp | ntp | >= 4.3.0 < 4.3.93 | 4.3.93 |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
| oracle | solaris | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | manager_proxy | — | — |
| suse | openstack_cloud | — | — |
CVSS provenance
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
vendor_ubuntu6.5MEDIUM
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC NET CP 443-1 OPC UA
cisa_ics·2021-06-08·CVSS 5.9
[MEDIUM] Siemens SIMATIC NET CP 443-1 OPC UA
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC NET CP 443-1 OPC UA
Last RevisedJune 08, 2021
Alert CodeICSA-21-159-11
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC NET CP 443-1 OPC UA
- Vulnerabilities: Improper Input Validation, Improper Restriction of Operations within the Bounds of a Memory Buffer, Incorrect Calculation, Classic Buffer Overflow, Improper Authentication, Race Condition, Data Processing Errors, Exposure of Sensitive Information to an Unauthorized Actor, Out-of-bounds Read
## 2. RISK EVALUATION
Succes
CISA ICS
Siemens TIM 4R-IE Devices
cisa_ics·2021-04-13·CVSS 7.5
[HIGH] Siemens TIM 4R-IE Devices
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens TIM 4R-IE Devices
Last RevisedApril 13, 2021
Alert CodeICSA-21-103-11
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: TIM 4R-IE
- Vulnerabilities: Incorrect Type Conversion or Cast, Improper Input Validation, Improper Authentication, Security Features, Null Pointer Dereference, Data Processing Errors, Exposure of Sensitive Information to an Unauthorized Actor, Race Condition
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could compromise the confidentiality, integri
Ubuntu
NTP vulnerabilities
vendor_ubuntu·2016-10-05·CVSS 6.5
CVE-2015-7973 [MEDIUM] NTP vulnerabilities
Title: NTP vulnerabilities
Summary: Several security issues were fixed in NTP.
Aanchal Malhotra discovered that NTP incorrectly handled authenticated
broadcast mode. A remote attacker could use this issue to perform a replay
attack. (CVE-2015-7973)
Matt Street discovered that NTP incorrectly verified peer associations of
symmetric keys. A remote attacker could use this issue to perform an
impersonation attack. (CVE-2015-7974)
Jonathan Gardner discovered that the NTP ntpq utility incorrectly handled
memory. An attacker could possibly use this issue to cause ntpq to crash,
resulting in a denial of service. This issue only affected Ubuntu 16.04
LTS. (CVE-2015-7975)
Jonathan Gardner discovered that the NTP ntpq utility incorrectly handled
dangerous characters in filenames. An attacker cou
Red Hat
ntp: broadcast interleave (incomplete fix for CVE-2016-1548)
vendor_redhat·2016-06-02·CVSS 7.2
CVE-2016-4956 [HIGH] ntp: broadcast interleave (incomplete fix for CVE-2016-1548)
ntp: broadcast interleave (incomplete fix for CVE-2016-1548)
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-1548.
Mitigation: Do not use NTP's broadcast mode in the clients by not configuring the "broadcastclient" directive in the ntp.conf file.
Package: ntp (Red Hat Enterprise Linux 5) - Will not fix
Package: ntp (Red Hat Enterprise Linux 6) - Will not fix
Package: ntp (Red Hat Enterprise Linux 7) - Will not fix
BSD
FreeBSD-SA-16:16.ntp: Multiple vulnerabilities of ntp
bsd_advisories·2016-04-29·CVSS 5.3
CVE-2016-1547 [MEDIUM] FreeBSD-SA-16:16.ntp: Multiple vulnerabilities of ntp
FreeBSD-SA-16:16.ntp Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities of ntp
Category: contrib
Module: ntp
Announced: 2016-04-29
Credits: Network Time Foundation and various contributors listed below
Affects: All supported versions of FreeBSD.
Corrected: 2016-04-27 15:24:33 UTC (stable/10, 10.3-STABLE)
2016-04-29 08:02:31 UTC (releng/10.3, 10.3-RELEASE-p1)
2016-04-29 08:02:31 UTC (releng/10.2, 10.2-RELEASE-p15)
2016-04-29 08:02:31 UTC (releng/10.1, 10.1-RELEASE-p32)
2016-04-27 15:25:18 UTC (stable/9, 9.3-STABLE)
2016-04-29 08:02:31 UTC (releng/9.3, 9.3-RELEASE-p40)
CVE Name: CVE-2016-1547, CVE-2016-1548, CVE-2016-1549, CVE-2016-1550,
CVE-2016-1551, CVE-2016-2516, CVE-2016-2517, CVE-2016-2518,
CVE-2016-2519
For general information regarding FreeBSD Security Advisorie
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
vendor_cisco·2016-04-28·CVSS 5.3
CVE-2015-7704 [MEDIUM] Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
Multiple Cisco products incorporate a version of the Network Time Protocol daemon (ntpd) package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or modify the time being advertised by a device acting as a Network Time Protocol (NTP) server.
On April 26, 2016, the NTP Consortium of the Network Time Foundation released a security notice that details 11 issues regarding DoS vulnerabilities, information disclosure vulnerabilities, and logic issues that may allow an attacker to shift a system's time. Two of the vulnerabilities disclosed in the NTP security notice address issues that
Red Hat
ntp: ntpd switching to interleaved mode with spoofed packets
vendor_redhat·2016-04-26·CVSS 7.2
CVE-2016-1548 [HIGH] ntp: ntpd switching to interleaved mode with spoofed packets
ntp: ntpd switching to interleaved mode with spoofed packets
An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timestamp recorded for that server. After making this switch, the client in NTP 4.2.8p4 and earlier and NTPSec aa48d001683e5b791a743ec9c575aaf7d867a2b0c will reject all future legitimate server responses. It is possible to force the victim client to move time after the mode has been changed. ntpq gives no indication that the mode has been switched.
It was found that an ntpd client could be forced to change from basic client/server mode to the interleaved symmetric mode. A remote attacker could use a spoofed packet that, when processed by an ntpd client, would cause that client to reject all future legitimate server r
Debian
CVE-2016-4956: ntp - ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of serv...
vendor_debian·2016·CVSS 7.2
CVE-2016-4956 [HIGH] CVE-2016-4956: ntp - ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of serv...
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-1548.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p8+dfsg-1)
Debian
CVE-2016-1548: ntp - An attacker can spoof a packet from a legitimate ntpd server with an origin time...
vendor_debian·2016·CVSS 7.2
CVE-2016-1548 [HIGH] CVE-2016-1548: ntp - An attacker can spoof a packet from a legitimate ntpd server with an origin time...
An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timestamp recorded for that server. After making this switch, the client in NTP 4.2.8p4 and earlier and NTPSec aa48d001683e5b791a743ec9c575aaf7d867a2b0c will reject all future legitimate server responses. It is possible to force the victim client to move time after the mode has been changed. ntpq gives no indication that the mode has been switched.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p7+dfsg-1)
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
vendor_cisco
CVE-2016-1548 Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
CVE-2016-1548: Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
Multiple Cisco products incorporate a version of the Network Time Protocol daemon (ntpd) package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or modify the time being advertised by a device acting as a Network Time Protocol (NTP) server. On April 26, 2016, the NTP Consortium of the Network Time Foundation released a security notice that
Bug IDs: CSCuz44082, CSCuz44085, CSCuz44088, CSCuz44082, CSCuz44085
GHSA
GHSA-fp4r-m88r-wmm8: An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timestamp recorded for that server
ghsa_unreviewed·2022-05-13
CVE-2016-1548 [HIGH] GHSA-fp4r-m88r-wmm8: An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timestamp recorded for that server
An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timestamp recorded for that server. After making this switch, the client in NTP 4.2.8p4 and earlier and NTPSec aa48d001683e5b791a743ec9c575aaf7d867a2b0c will reject all future legitimate server responses. It is possible to force the victim client to move time after the mode has been changed. ntpq gives no indication that the mode has been switched.
GHSA
GHSA-3cjf-rf3w-p8j9: ntpd in NTP 4
ghsa_unreviewed·2022-05-13·CVSS 7.2
CVE-2016-4956 [HIGH] GHSA-3cjf-rf3w-p8j9: ntpd in NTP 4
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-1548.
OSV
CVE-2016-1548: An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timestamp recorded for that server
osv·2017-01-06·CVSS 7.2
CVE-2016-1548 [HIGH] CVE-2016-1548: An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timestamp recorded for that server
An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timestamp recorded for that server. After making this switch, the client in NTP 4.2.8p4 and earlier and NTPSec aa48d001683e5b791a743ec9c575aaf7d867a2b0c will reject all future legitimate server responses. It is possible to force the victim client to move time after the mode has been changed. ntpq gives no indication that the mode has been switched.
OSV
ntp vulnerabilities
osv·2016-10-05·CVSS 6.5
CVE-2015-7973 [MEDIUM] ntp vulnerabilities
ntp vulnerabilities
Aanchal Malhotra discovered that NTP incorrectly handled authenticated
broadcast mode. A remote attacker could use this issue to perform a replay
attack. (CVE-2015-7973)
Matt Street discovered that NTP incorrectly verified peer associations of
symmetric keys. A remote attacker could use this issue to perform an
impersonation attack. (CVE-2015-7974)
Jonathan Gardner discovered that the NTP ntpq utility incorrectly handled
memory. An attacker could possibly use this issue to cause ntpq to crash,
resulting in a denial of service. This issue only affected Ubuntu 16.04
LTS. (CVE-2015-7975)
Jonathan Gardner discovered that the NTP ntpq utility incorrectly handled
dangerous characters in filenames. An attacker could possibly use this
issue to overwrite arbitrary files. (CV
OSV
CVE-2016-4956: ntpd in NTP 4
osv·2016-07-05·CVSS 7.2
CVE-2016-4956 [HIGH] CVE-2016-4956: ntpd in NTP 4
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-1548.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4956 ntp: broadcast interleave (incomplete fix for CVE-2016-1548)
bugzilla·2016-05-30·CVSS 7.2
CVE-2016-4956 [HIGH] CVE-2016-4956 ntp: broadcast interleave (incomplete fix for CVE-2016-1548)
CVE-2016-4956 ntp: broadcast interleave (incomplete fix for CVE-2016-1548)
It was found that the fix for CVE-2016-1548 did not cover broadcast associations; broadcast clients could be triggered to flip into interleave mode and be exposed to the same vulnerability as described in CVE-2016-1548 (bug 1331462).
Discussion:
Acknowledgments:
Name: Miroslav Lichvar (Red Hat)
---
Mitigation:
Do not use NTP's broadcast mode in the clients by not configuring the "broadcastclient" directive in the ntp.conf file.
---
Created ntp tracking bugs for this issue:
Affects: fedora-all [bug 1342128]
---
Upstream bug:
http://support.ntp.org/bin/view/Main/NtpBug3042
External References:
http://support.ntp.org/bin/view/Main/SecurityNotice#June_2016_ntp_4_2_8p8_NTP_Securi
---
Could anyone suggest
Bugzilla
CVE-2016-1548 CVE-2016-1549 CVE-2016-1550 CVE-2016-2516 CVE-2016-2517 CVE-2016-2518 ntp: various flaws [fedora-all]
bugzilla·2016-05-02·CVSS 7.2
CVE-2016-1548 [HIGH] CVE-2016-1548 CVE-2016-1549 CVE-2016-1550 CVE-2016-2516 CVE-2016-2517 CVE-2016-2518 ntp: various flaws [fedora-all]
CVE-2016-1548 CVE-2016-1549 CVE-2016-1550 CVE-2016-2516 CVE-2016-2517 CVE-2016-2518 ntp: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2016-1548 ntp: ntpd switching to interleaved mode with spoofed packets
bugzilla·2016-04-28·CVSS 7.2
CVE-2016-1548 [HIGH] CVE-2016-1548 ntp: ntpd switching to interleaved mode with spoofed packets
CVE-2016-1548 ntp: ntpd switching to interleaved mode with spoofed packets
ntpd supports an interleaved mode to allow the protocol to exchange transmit timestamps that were captured after the packet was sent in symmetric associations and broadcast modes. It can be enabled in the configuration file, but it's also enabled automatically when a packet received from the source is detected to be in the interleaved mode. The detection compares the origin timestamp in the packet to the previous local receive timestamp. The interleaved mode is enabled even in client associations, even though it makes no sense there.
The problem is that the reference timestamp, which is revealed in all packets, is set to the local receive timestamp when the clock is updated. An off-path attacker can use ordinary c
Talos
Vulnerability Spotlight: Further NTPD Vulnerabilities
blogs_talos·2016-04-27·CVSS 5.3
[MEDIUM] Vulnerability Spotlight: Further NTPD Vulnerabilities
## Vulnerability Spotlight: Further NTPD Vulnerabilities
As a member of the Linux Foundation Core Infrastructure Initiative , Cisco is contributing to the CII effort by evaluating the Network Time Protocol daemon (ntpd) for security defects. We previously identified a series of vulnerabilities in the Network Time Protocol daemon; through our continued research we have identified further vulnerabilities in the software.
Since 2013, criminals have been abusing NTP packets in order to cause amplified denial of service attacks . The ubiquity of the Network Time Protocol daemon and the importance of co-ordinated time for the correct functioning of many services means that it is a tempting target for attack. Vulnerabilities that allow the time as understood by ntpd to be altered can be used by
Talos
Vulnerability Spotlight: Further NTPD Vulnerabilities
blogs_talos·2016-04-27·CVSS 5.3
[MEDIUM] Vulnerability Spotlight: Further NTPD Vulnerabilities
As a member of the Linux Foundation Core Infrastructure Initiative, Cisco is contributing to the CII effort by evaluating the Network Time Protocol daemon (ntpd) for security defects. We previously identified a series of vulnerabilities in the Network Time Protocol daemon; through our continued research we have identified further vulnerabilities in the software.
Since 2013, criminals have been abusing NTP packets in order to cause amplified denial of service attacks. The ubiquity of the Network Time Protocol daemon and the importance of co-ordinated time for the correct functioning of many services means that it is a tempting target for attack. Vulnerabilities that allow the time as understood by ntpd to be altered can be used by attackers to set the time to an arbitrary value. This allow
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/183647.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-May/184669.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00037.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00052.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00042.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00114.htmlhttp://packetstormsecurity.com/files/136864/Slackware-Security-Advisory-ntp-Updates.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1552.htmlhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160428-ntpdhttp://www.debian.org/security/2016/dsa-3629http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securityfocus.com/archive/1/538233/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/538233/100/0/threadedhttp://www.securityfocus.com/bid/88264http://www.securitytracker.com/id/1035705http://www.talosintelligence.com/reports/TALOS-2016-0082/http://www.ubuntu.com/usn/USN-3096-1https://access.redhat.com/errata/RHSA-2016:1141https://cert-portal.siemens.com/productcert/pdf/ssa-211752.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-497656.pdfhttps://security.FreeBSD.org/advisories/FreeBSD-SA-16:16.ntp.aschttps://security.gentoo.org/glsa/201607-15https://security.netapp.com/advisory/ntap-20171004-0002/https://us-cert.cisa.gov/ics/advisories/icsa-21-103-11https://us-cert.cisa.gov/ics/advisories/icsa-21-159-11https://www.arista.com/en/support/advisories-notices/security-advisories/1332-security-advisory-19https://www.debian.org/security/2016/dsa-3629https://www.kb.cert.org/vuls/id/718152https://www.talosintelligence.com/vulnerability_reports/TALOS-2016-0082http://lists.fedoraproject.org/pipermail/package-announce/2016-May/183647.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-May/184669.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00037.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00052.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00042.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00114.htmlhttp://packetstormsecurity.com/files/136864/Slackware-Security-Advisory-ntp-Updates.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1552.htmlhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160428-ntpdhttp://www.debian.org/security/2016/dsa-3629http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securityfocus.com/archive/1/538233/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/538233/100/0/threadedhttp://www.securityfocus.com/bid/88264http://www.securitytracker.com/id/1035705http://www.talosintelligence.com/reports/TALOS-2016-0082/http://www.ubuntu.com/usn/USN-3096-1https://access.redhat.com/errata/RHSA-2016:1141https://cert-portal.siemens.com/productcert/pdf/ssa-211752.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-497656.pdfhttps://security.FreeBSD.org/advisories/FreeBSD-SA-16:16.ntp.aschttps://security.gentoo.org/glsa/201607-15https://security.netapp.com/advisory/ntap-20171004-0002/https://us-cert.cisa.gov/ics/advisories/icsa-21-103-11https://us-cert.cisa.gov/ics/advisories/icsa-21-159-11https://www.arista.com/en/support/advisories-notices/security-advisories/1332-security-advisory-19https://www.debian.org/security/2016/dsa-3629https://www.kb.cert.org/vuls/id/718152https://www.talosintelligence.com/vulnerability_reports/TALOS-2016-0082
2017-01-06
Published