CVE-2016-2516
published 2017-01-30CVE-2016-2516: NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote attackers to cause a denial of service (ntpd abort) by using the same IP…
PriorityP429medium5.3CVSS 3.0
AVNACHPRLUINSUCNINAH
EPSS
8.95%
94.7th percentile
NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote attackers to cause a denial of service (ntpd abort) by using the same IP address multiple times in an unconfig directive.
Affected
97 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ntp | < ntp 1:4.2.8p7+dfsg-1 (bullseye) | ntp 1:4.2.8p7+dfsg-1 (bullseye) |
| ntp | ntp | <= 4.2.8 | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_cisco5.3MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
NTP vulnerabilities
vendor_ubuntu·2016-10-05·CVSS 6.5
CVE-2015-7973 [MEDIUM] NTP vulnerabilities
Title: NTP vulnerabilities
Summary: Several security issues were fixed in NTP.
Aanchal Malhotra discovered that NTP incorrectly handled authenticated
broadcast mode. A remote attacker could use this issue to perform a replay
attack. (CVE-2015-7973)
Matt Street discovered that NTP incorrectly verified peer associations of
symmetric keys. A remote attacker could use this issue to perform an
impersonation attack. (CVE-2015-7974)
Jonathan Gardner discovered that the NTP ntpq utility incorrectly handled
memory. An attacker could possibly use this issue to cause ntpq to crash,
resulting in a denial of service. This issue only affected Ubuntu 16.04
LTS. (CVE-2015-7975)
Jonathan Gardner discovered that the NTP ntpq utility incorrectly handled
dangerous characters in filenames. An attacker cou
BSD
FreeBSD-SA-16:16.ntp: Multiple vulnerabilities of ntp
bsd_advisories·2016-04-29·CVSS 5.3
CVE-2016-1547 [MEDIUM] FreeBSD-SA-16:16.ntp: Multiple vulnerabilities of ntp
FreeBSD-SA-16:16.ntp Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities of ntp
Category: contrib
Module: ntp
Announced: 2016-04-29
Credits: Network Time Foundation and various contributors listed below
Affects: All supported versions of FreeBSD.
Corrected: 2016-04-27 15:24:33 UTC (stable/10, 10.3-STABLE)
2016-04-29 08:02:31 UTC (releng/10.3, 10.3-RELEASE-p1)
2016-04-29 08:02:31 UTC (releng/10.2, 10.2-RELEASE-p15)
2016-04-29 08:02:31 UTC (releng/10.1, 10.1-RELEASE-p32)
2016-04-27 15:25:18 UTC (stable/9, 9.3-STABLE)
2016-04-29 08:02:31 UTC (releng/9.3, 9.3-RELEASE-p40)
CVE Name: CVE-2016-1547, CVE-2016-1548, CVE-2016-1549, CVE-2016-1550,
CVE-2016-1551, CVE-2016-2516, CVE-2016-2517, CVE-2016-2518,
CVE-2016-2519
For general information regarding FreeBSD Security Advisorie
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
vendor_cisco·2016-04-28·CVSS 5.3
CVE-2015-7704 [MEDIUM] Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
Multiple Cisco products incorporate a version of the Network Time Protocol daemon (ntpd) package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or modify the time being advertised by a device acting as a Network Time Protocol (NTP) server.
On April 26, 2016, the NTP Consortium of the Network Time Foundation released a security notice that details 11 issues regarding DoS vulnerabilities, information disclosure vulnerabilities, and logic issues that may allow an attacker to shift a system's time. Two of the vulnerabilities disclosed in the NTP security notice address issues that
Red Hat
ntp: assertion failure in ntpd on duplicate IPs on unconfig directives
vendor_redhat·2016-04-26·CVSS 5.3
CVE-2016-2516 [MEDIUM] ntp: assertion failure in ntpd on duplicate IPs on unconfig directives
ntp: assertion failure in ntpd on duplicate IPs on unconfig directives
NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote attackers to cause a denial of service (ntpd abort) by using the same IP address multiple times in an unconfig directive.
Mitigation: Disable remote configuration of NTP, or restrict this ability to trusted users.
Package: ntp (Red Hat Enterprise Linux 5) - Not affected
Package: ntp (Red Hat Enterprise Linux 6) - Will not fix
Package: ntp (Red Hat Enterprise Linux 7) - Will not fix
Red Hat
ntp: certain remote configuration values not properly validated
vendor_redhat·2016-04-26·CVSS 5.3
CVE-2016-2517 [MEDIUM] ntp: certain remote configuration values not properly validated
ntp: certain remote configuration values not properly validated
NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (prevent subsequent authentication) by leveraging knowledge of the controlkey or requestkey and sending a crafted packet to ntpd, which changes the value of trustedkey, controlkey, or requestkey. NOTE: this vulnerability exists because of a CVE-2016-2516 regression.
Statement: Red Hat Product Security does not consider this to be a security issue. An authenticated user could use various other means to disable access to an NTP server (for example, using the 'restrict' command). To mitigate this issue, disable remote configuration of NTP, or restrict this ability to trusted users.
Package: ntp (Red Hat Enterprise Linux 5) - Not aff
Debian
CVE-2016-2516: ntp - NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote...
vendor_debian·2016·CVSS 5.3
CVE-2016-2516 [MEDIUM] CVE-2016-2516: ntp - NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote...
NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote attackers to cause a denial of service (ntpd abort) by using the same IP address multiple times in an unconfig directive.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p7+dfsg-1)
Debian
CVE-2016-2517: ntp - NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a de...
vendor_debian·2016·CVSS 5.3
CVE-2016-2517 [MEDIUM] CVE-2016-2517: ntp - NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a de...
NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (prevent subsequent authentication) by leveraging knowledge of the controlkey or requestkey and sending a crafted packet to ntpd, which changes the value of trustedkey, controlkey, or requestkey. NOTE: this vulnerability exists because of a CVE-2016-2516 regression.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p7+dfsg-1)
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
vendor_cisco
CVE-2016-2516 Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
CVE-2016-2516: Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
Multiple Cisco products incorporate a version of the Network Time Protocol daemon (ntpd) package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or modify the time being advertised by a device acting as a Network Time Protocol (NTP) server. On April 26, 2016, the NTP Consortium of the Network Time Foundation released a security notice that
Bug IDs: CSCuz44082, CSCuz44085, CSCuz44088, CSCuz44082, CSCuz44085
GHSA
GHSA-r7jh-6376-3vr2: NTP before 4
ghsa_unreviewed·2022-05-17
CVE-2016-2516 [HIGH] CWE-20 GHSA-r7jh-6376-3vr2: NTP before 4
NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote attackers to cause a denial of service (ntpd abort) by using the same IP address multiple times in an unconfig directive.
GHSA
GHSA-3gmh-m5h5-5234: NTP before 4
ghsa_unreviewed·2022-05-17·CVSS 5.3
CVE-2016-2517 [MEDIUM] CWE-20 GHSA-3gmh-m5h5-5234: NTP before 4
NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (prevent subsequent authentication) by leveraging knowledge of the controlkey or requestkey and sending a crafted packet to ntpd, which changes the value of trustedkey, controlkey, or requestkey. NOTE: this vulnerability exists because of a CVE-2016-2516 regression.
OSV
CVE-2016-2517: NTP before 4
osv·2017-01-30·CVSS 5.3
CVE-2016-2517 [MEDIUM] CVE-2016-2517: NTP before 4
NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (prevent subsequent authentication) by leveraging knowledge of the controlkey or requestkey and sending a crafted packet to ntpd, which changes the value of trustedkey, controlkey, or requestkey. NOTE: this vulnerability exists because of a CVE-2016-2516 regression.
OSV
CVE-2016-2516: NTP before 4
osv·2017-01-30·CVSS 5.3
CVE-2016-2516 [MEDIUM] CVE-2016-2516: NTP before 4
NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote attackers to cause a denial of service (ntpd abort) by using the same IP address multiple times in an unconfig directive.
OSV
ntp vulnerabilities
osv·2016-10-05·CVSS 6.5
CVE-2015-7973 [MEDIUM] ntp vulnerabilities
ntp vulnerabilities
Aanchal Malhotra discovered that NTP incorrectly handled authenticated
broadcast mode. A remote attacker could use this issue to perform a replay
attack. (CVE-2015-7973)
Matt Street discovered that NTP incorrectly verified peer associations of
symmetric keys. A remote attacker could use this issue to perform an
impersonation attack. (CVE-2015-7974)
Jonathan Gardner discovered that the NTP ntpq utility incorrectly handled
memory. An attacker could possibly use this issue to cause ntpq to crash,
resulting in a denial of service. This issue only affected Ubuntu 16.04
LTS. (CVE-2015-7975)
Jonathan Gardner discovered that the NTP ntpq utility incorrectly handled
dangerous characters in filenames. An attacker could possibly use this
issue to overwrite arbitrary files. (CV
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-1548 CVE-2016-1549 CVE-2016-1550 CVE-2016-2516 CVE-2016-2517 CVE-2016-2518 ntp: various flaws [fedora-all]
bugzilla·2016-05-02·CVSS 7.2
CVE-2016-1548 [HIGH] CVE-2016-1548 CVE-2016-1549 CVE-2016-1550 CVE-2016-2516 CVE-2016-2517 CVE-2016-2518 ntp: various flaws [fedora-all]
CVE-2016-1548 CVE-2016-1549 CVE-2016-1550 CVE-2016-2516 CVE-2016-2517 CVE-2016-2518 ntp: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2016-2516 ntp: assertion failure in ntpd on duplicate IPs on unconfig directives
bugzilla·2016-04-28·CVSS 5.3
CVE-2016-2516 [MEDIUM] CVE-2016-2516 ntp: assertion failure in ntpd on duplicate IPs on unconfig directives
CVE-2016-2516 ntp: assertion failure in ntpd on duplicate IPs on unconfig directives
The following flaw was found in ntpd:
If ntpd was expressly configured to allow for remote configuration, a malicious user who knows the controlkey for ntpq or the requestkey for ntpdc (if mode7 is expressly enabled) can create a session with ntpd and if an existing association is unconfigured using the same IP twice on the unconfig directive line, ntpd will abort.
Upstream bugs:
http://support.ntp.org/bin/view/Main/NtpBug3011
External References:
http://support.ntp.org/bin/view/Main/SecurityNotice#April_2016_NTP_4_2_8p7_Security
Discussion:
Created ntp tracking bugs for this issue:
Affects: fedora-all [bug 1332160]
---
Mitigation:
Disable remote configuration of NTP, or restrict this ability t
http://support.ntp.org/bin/view/Main/NtpBug3011http://www.debian.org/security/2016/dsa-3629http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/88180http://www.securitytracker.com/id/1035705https://security.FreeBSD.org/advisories/FreeBSD-SA-16:16.ntp.aschttps://security.gentoo.org/glsa/201607-15https://security.netapp.com/advisory/ntap-20171004-0002/https://www.kb.cert.org/vuls/id/718152http://support.ntp.org/bin/view/Main/NtpBug3011http://www.debian.org/security/2016/dsa-3629http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/88180http://www.securitytracker.com/id/1035705https://security.FreeBSD.org/advisories/FreeBSD-SA-16:16.ntp.aschttps://security.gentoo.org/glsa/201607-15https://security.netapp.com/advisory/ntap-20171004-0002/https://www.kb.cert.org/vuls/id/718152
2017-01-30
Published