CVE-2016-2519Improper Restriction of Operations within the Bounds of a Memory Buffer in NTP

Severity
5.9MEDIUMNVD
EPSS
9.5%
top 7.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 30
Latest updateMay 17

Description

ntpd in NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (ntpd abort) by a large request data value, which triggers the ctl_getitem function to return a NULL value.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages4 packages

debiandebian/ntp< ntp 1:4.2.8p7+dfsg-1 (bullseye)
Debianntp/ntp< 1:4.2.8p7+dfsg-1
Ubuntuntp/ntp< 1:4.2.6.p5+dfsg-3ubuntu2.14.04.11+1
NVDntp/ntp4.2.8+92

🔴Vulnerability Details

3
GHSA
GHSA-m47g-h2c2-mq2w: ntpd in NTP before 42022-05-17
OSV
ntp vulnerabilities2017-07-05
OSV
CVE-2016-2519: ntpd in NTP before 42017-01-30

📋Vendor Advisories

6
Ubuntu
NTP vulnerabilities2017-07-05
BSD
FreeBSD-SA-16:16.ntp: Multiple vulnerabilities of ntp2016-04-29
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 20162016-04-28
Red Hat
ntp: ctl_getitem() return value not always checked2016-04-26
Debian
CVE-2016-2519: ntp - ntpd in NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to ca...2016

💬Community

1
Bugzilla
CVE-2016-2519 ntp: ctl_getitem() return value not always checked2016-04-28