CVE-2016-2517Improper Input Validation in NTP

Severity
5.3MEDIUMNVD
EPSS
3.0%
top 13.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 30
Latest updateMay 17

Description

NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (prevent subsequent authentication) by leveraging knowledge of the controlkey or requestkey and sending a crafted packet to ntpd, which changes the value of trustedkey, controlkey, or requestkey. NOTE: this vulnerability exists because of a CVE-2016-2516 regression.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.6 | Impact: 3.6

Affected Packages3 packages

debiandebian/ntp< ntp 1:4.2.8p7+dfsg-1 (bullseye)
Debianntp/ntp< 1:4.2.8p7+dfsg-1
NVDntp/ntp4.2.8+92

🔴Vulnerability Details

2
GHSA
GHSA-3gmh-m5h5-5234: NTP before 42022-05-17
OSV
CVE-2016-2517: NTP before 42017-01-30

📋Vendor Advisories

5
BSD
FreeBSD-SA-16:16.ntp: Multiple vulnerabilities of ntp2016-04-29
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 20162016-04-28
Red Hat
ntp: certain remote configuration values not properly validated2016-04-26
Debian
CVE-2016-2517: ntp - NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a de...2016
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016

💬Community

2
Bugzilla
CVE-2016-1548 CVE-2016-1549 CVE-2016-1550 CVE-2016-2516 CVE-2016-2517 CVE-2016-2518 ntp: various flaws [fedora-all]2016-05-02
Bugzilla
CVE-2016-2517 ntp: certain remote configuration values not properly validated2016-04-28