CVE-2016-4954
published 2016-07-05CVE-2016-4954: The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification)…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
13.21%
95.9th percentile
The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstrated by triggering an incorrect leap indication.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ntp | < ntp 1:4.2.8p8+dfsg-1 (bullseye) | ntp 1:4.2.8p8+dfsg-1 (bullseye) |
| ntp | ntp | — | — |
| ntp | ntp | >= 0 < 1:4.2.8p8+dfsg-1 | 1:4.2.8p8+dfsg-1 |
| ntp | ntp | >= 0 < 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 | 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 |
| ntp | ntp | >= 0 < 1:4.2.8p4+dfsg-3ubuntu5.3 | 1:4.2.8p4+dfsg-3ubuntu5.3 |
| ntp | ntp | >= 4.2.0 < 4.2.8 | 4.2.8 |
| ntp | ntp | >= 4.3.0 < 4.3.93 | 4.3.93 |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
| oracle | solaris | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | manager | — | — |
| suse | manager_proxy | — | — |
| suse | openstack_cloud | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC NET CP 443-1 OPC UA
cisa_ics·2021-06-08·CVSS 5.9
[MEDIUM] Siemens SIMATIC NET CP 443-1 OPC UA
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC NET CP 443-1 OPC UA
Last RevisedJune 08, 2021
Alert CodeICSA-21-159-11
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC NET CP 443-1 OPC UA
- Vulnerabilities: Improper Input Validation, Improper Restriction of Operations within the Bounds of a Memory Buffer, Incorrect Calculation, Classic Buffer Overflow, Improper Authentication, Race Condition, Data Processing Errors, Exposure of Sensitive Information to an Unauthorized Actor, Out-of-bounds Read
## 2. RISK EVALUATION
Succes
CISA ICS
Siemens TIM 4R-IE Devices
cisa_ics·2021-04-13·CVSS 7.5
[HIGH] Siemens TIM 4R-IE Devices
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens TIM 4R-IE Devices
Last RevisedApril 13, 2021
Alert CodeICSA-21-103-11
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: TIM 4R-IE
- Vulnerabilities: Incorrect Type Conversion or Cast, Improper Input Validation, Improper Authentication, Security Features, Null Pointer Dereference, Data Processing Errors, Exposure of Sensitive Information to an Unauthorized Actor, Race Condition
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could compromise the confidentiality, integri
Ubuntu
NTP vulnerabilities
vendor_ubuntu·2016-10-05·CVSS 6.5
CVE-2015-7973 [MEDIUM] NTP vulnerabilities
Title: NTP vulnerabilities
Summary: Several security issues were fixed in NTP.
Aanchal Malhotra discovered that NTP incorrectly handled authenticated
broadcast mode. A remote attacker could use this issue to perform a replay
attack. (CVE-2015-7973)
Matt Street discovered that NTP incorrectly verified peer associations of
symmetric keys. A remote attacker could use this issue to perform an
impersonation attack. (CVE-2015-7974)
Jonathan Gardner discovered that the NTP ntpq utility incorrectly handled
memory. An attacker could possibly use this issue to cause ntpq to crash,
resulting in a denial of service. This issue only affected Ubuntu 16.04
LTS. (CVE-2015-7975)
Jonathan Gardner discovered that the NTP ntpq utility incorrectly handled
dangerous characters in filenames. An attacker cou
BSD
FreeBSD-SA-16:24.ntp: Multiple vulnerabilities of ntp
bsd_advisories·2016-06-04·CVSS 7.5
CVE-2016-4953 [HIGH] FreeBSD-SA-16:24.ntp: Multiple vulnerabilities of ntp
FreeBSD-SA-16:24.ntp Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities of ntp
Category: contrib
Module: ntp
Announced: 2016-06-04
Credits: Network Time Foundation and various contributors listed below
Affects: All supported versions of FreeBSD.
Corrected: 2016-06-03 08:59:21 UTC (stable/10, 10.3-STABLE)
2016-06-04 05:46:52 UTC (releng/10.3, 10.3-RELEASE-p5)
2016-06-04 05:46:52 UTC (releng/10.2, 10.2-RELEASE-p19)
2016-06-04 05:46:52 UTC (releng/10.1, 10.1-RELEASE-p36)
2016-06-03 09:03:10 UTC (stable/9, 9.3-STABLE)
2016-06-04 05:46:52 UTC (releng/9.3, 9.3-RELEASE-p44)
CVE Name: CVE-2016-4957, CVE-2016-4953, CVE-2016-4954, CVE-2016-4955
CVE-2016-4956
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branc
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016
vendor_cisco·2016-06-03
CVE-2016-4953 [HIGH] Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016
Multiple Cisco products incorporate a version of the Network Time Protocol daemon (ntpd) package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or modify the time being advertised by a device acting as a Network Time Protocol (NTP) server.
On June 2, 2016, the NTP Consortium of the Network Time Foundation released a security notice that details five issues regarding DoS vulnerabilities and logic issues that may allow an attacker to shift a system's time.
The new vulnerabilities disclosed in this document are as follows:
Network Time Protocol CRYPTO-NAK Denial of Service Vuln
Red Hat
ntp: partial processing of spoofed packets
vendor_redhat·2016-06-02·CVSS 7.5
CVE-2016-4954 [HIGH] ntp: partial processing of spoofed packets
ntp: partial processing of spoofed packets
The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstrated by triggering an incorrect leap indication.
Package: ntp (Red Hat Enterprise Linux 5) - Will not fix
Package: ntp (Red Hat Enterprise Linux 6) - Will not fix
Package: ntp (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2016-4954: ntp - The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 all...
vendor_debian·2016·CVSS 7.5
CVE-2016-4954 [HIGH] CVE-2016-4954: ntp - The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 all...
The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstrated by triggering an incorrect leap indication.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p8+dfsg-1)
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016
vendor_cisco
CVE-2016-4954 Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016
CVE-2016-4954: Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016
Multiple Cisco products incorporate a version of the Network Time Protocol daemon (ntpd) package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or modify the time being advertised by a device acting as a Network Time Protocol (NTP) server. On June 2, 2016, the NTP Consortium of the Network Time Foundation released a security notice that
Bug IDs: CSCuz92606, CSCuz92609, CSCuz92629, CSCuz92606, CSCuz92609
GHSA
GHSA-w5gw-rhc6-c5g8: The process_packet function in ntp_proto
ghsa_unreviewed·2022-05-13
CVE-2016-4954 [HIGH] CWE-362 GHSA-w5gw-rhc6-c5g8: The process_packet function in ntp_proto
The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstrated by triggering an incorrect leap indication.
OSV
ntp vulnerabilities
osv·2016-10-05·CVSS 6.5
CVE-2015-7973 [MEDIUM] ntp vulnerabilities
ntp vulnerabilities
Aanchal Malhotra discovered that NTP incorrectly handled authenticated
broadcast mode. A remote attacker could use this issue to perform a replay
attack. (CVE-2015-7973)
Matt Street discovered that NTP incorrectly verified peer associations of
symmetric keys. A remote attacker could use this issue to perform an
impersonation attack. (CVE-2015-7974)
Jonathan Gardner discovered that the NTP ntpq utility incorrectly handled
memory. An attacker could possibly use this issue to cause ntpq to crash,
resulting in a denial of service. This issue only affected Ubuntu 16.04
LTS. (CVE-2015-7975)
Jonathan Gardner discovered that the NTP ntpq utility incorrectly handled
dangerous characters in filenames. An attacker could possibly use this
issue to overwrite arbitrary files. (CV
OSV
CVE-2016-4954: The process_packet function in ntp_proto
osv·2016-07-05·CVSS 7.5
CVE-2016-4954 [HIGH] CVE-2016-4954: The process_packet function in ntp_proto
The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstrated by triggering an incorrect leap indication.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8139 CVE-2016-4954 CVE-2016-4955 CVE-2016-4956 ntp: various flaws [fedora-all]
bugzilla·2016-06-02·CVSS 5.3
CVE-2015-8139 [MEDIUM] CVE-2015-8139 CVE-2016-4954 CVE-2016-4955 CVE-2016-4956 ntp: various flaws [fedora-all]
CVE-2015-8139 CVE-2016-4954 CVE-2016-4955 CVE-2016-4956 ntp: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2016-4954 ntp: partial processing of spoofed packets
bugzilla·2016-01-27·CVSS 7.5
CVE-2016-4954 [HIGH] CVE-2016-4954 ntp: partial processing of spoofed packets
CVE-2016-4954 ntp: partial processing of spoofed packets
Spoofed packets that failed some of the early NTP tests in the receive() function in ntp_proto.c may still enter the process_packet() function and set certain peer variables before the packet is actually dropped, which could be useful in some attacks on ntpd as a client.
For instance, with ntpd configured to use three servers it is possible to arm the leap second timer by setting the leap bits of the three sources. When a genuine packet is received and the clock is updated, the leap value will be overwritten for that source, but the two other sources will still be able to form a majority and arm the leap timer.
Disabling sources in the source selection by setting their leap or stratum as unsychronized could be useful in some cases
http://bugs.ntp.org/3044http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00042.htmlhttp://packetstormsecurity.com/files/137321/Slackware-Security-Advisory-ntp-Updates.htmlhttp://packetstormsecurity.com/files/137322/FreeBSD-Security-Advisory-FreeBSD-SA-16-24.ntp.htmlhttp://support.ntp.org/bin/view/Main/NtpBug3044http://support.ntp.org/bin/view/Main/SecurityNoticehttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160603-ntpdhttp://www.kb.cert.org/vuls/id/321640http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/archive/1/538599/100/0/threadedhttp://www.securityfocus.com/archive/1/538600/100/0/threadedhttp://www.securityfocus.com/archive/1/540683/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/538599/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/538600/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/540683/100/0/threadedhttp://www.securitytracker.com/id/1036037http://www.ubuntu.com/usn/USN-3096-1https://cert-portal.siemens.com/productcert/pdf/ssa-211752.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-497656.pdfhttps://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03757en_ushttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K3EYJQHJZ2KTVQ7ICEFHXTLZ36MRASWX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ORAMN3Q7TVJ54MBYF75XCJOE3DP7LYHT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNWGCQLW2VY72NIUYMJOCAKJKTXHDUK2/https://security.FreeBSD.org/advisories/FreeBSD-SA-16:24.ntp.aschttps://security.gentoo.org/glsa/201607-15https://us-cert.cisa.gov/ics/advisories/icsa-21-103-11https://us-cert.cisa.gov/ics/advisories/icsa-21-159-11https://www.kb.cert.org/vuls/id/321640http://bugs.ntp.org/3044http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00042.htmlhttp://packetstormsecurity.com/files/137321/Slackware-Security-Advisory-ntp-Updates.htmlhttp://packetstormsecurity.com/files/137322/FreeBSD-Security-Advisory-FreeBSD-SA-16-24.ntp.htmlhttp://support.ntp.org/bin/view/Main/NtpBug3044http://support.ntp.org/bin/view/Main/SecurityNoticehttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160603-ntpdhttp://www.kb.cert.org/vuls/id/321640http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/archive/1/538599/100/0/threadedhttp://www.securityfocus.com/archive/1/538600/100/0/threadedhttp://www.securityfocus.com/archive/1/540683/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/538599/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/538600/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/540683/100/0/threadedhttp://www.securitytracker.com/id/1036037http://www.ubuntu.com/usn/USN-3096-1https://cert-portal.siemens.com/productcert/pdf/ssa-211752.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-497656.pdfhttps://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03757en_ushttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K3EYJQHJZ2KTVQ7ICEFHXTLZ36MRASWX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ORAMN3Q7TVJ54MBYF75XCJOE3DP7LYHT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNWGCQLW2VY72NIUYMJOCAKJKTXHDUK2/https://security.FreeBSD.org/advisories/FreeBSD-SA-16:24.ntp.aschttps://security.gentoo.org/glsa/201607-15https://us-cert.cisa.gov/ics/advisories/icsa-21-103-11https://us-cert.cisa.gov/ics/advisories/icsa-21-159-11https://www.kb.cert.org/vuls/id/321640
2016-07-05
Published