CVE-2016-2516Improper Input Validation in NTP

Severity
5.3MEDIUMNVD
OSV6.5
EPSS
3.6%
top 12.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 30
Latest updateMay 17

Description

NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote attackers to cause a denial of service (ntpd abort) by using the same IP address multiple times in an unconfig directive.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.6 | Impact: 3.6

Affected Packages4 packages

debiandebian/ntp< ntp 1:4.2.8p7+dfsg-1 (bullseye)
Debianntp/ntp< 1:4.2.8p7+dfsg-1
Ubuntuntp/ntp< 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10+1
NVDntp/ntp4.2.8+92

🔴Vulnerability Details

5
GHSA
GHSA-r7jh-6376-3vr2: NTP before 42022-05-17
GHSA
GHSA-3gmh-m5h5-5234: NTP before 42022-05-17
OSV
CVE-2016-2517: NTP before 42017-01-30
OSV
CVE-2016-2516: NTP before 42017-01-30
OSV
ntp vulnerabilities2016-10-05

📋Vendor Advisories

8
Ubuntu
NTP vulnerabilities2016-10-05
BSD
FreeBSD-SA-16:16.ntp: Multiple vulnerabilities of ntp2016-04-29
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 20162016-04-28
Red Hat
ntp: assertion failure in ntpd on duplicate IPs on unconfig directives2016-04-26
Red Hat
ntp: certain remote configuration values not properly validated2016-04-26

💬Community

2
Bugzilla
CVE-2016-1548 CVE-2016-1549 CVE-2016-1550 CVE-2016-2516 CVE-2016-2517 CVE-2016-2518 ntp: various flaws [fedora-all]2016-05-02
Bugzilla
CVE-2016-2516 ntp: assertion failure in ntpd on duplicate IPs on unconfig directives2016-04-28