CVE-2016-4957
published 2016-07-05CVE-2016-4957: ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because…
PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
44.94%
98.7th percentile
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ntp | < ntp 1:4.2.8p8+dfsg-1 (bullseye) | ntp 1:4.2.8p8+dfsg-1 (bullseye) |
| novell | suse_manager | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | >= 0 < 1:4.2.8p8+dfsg-1 | 1:4.2.8p8+dfsg-1 |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
| oracle | solaris | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | manager_proxy | — | — |
| suse | openstack_cloud | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →A malicious crypto-NAK packet sent to a target running NTPD (NTP versions before 4.2.8p8, specifically 4.2.8p7) triggers a null pointer dereference in the valid_NAK() function, causing a segfault/daemon crash. No authentication is required to exploit this vulnerability. ↗
- →The vulnerable code path is in the valid_NAK() function in ntpd 4.2.8p7, which dereferences the peer pointer without null-checking it. Detect crashes/segfaults in ntpd processes as a sign of exploitation. ↗
- →The attack is unauthenticated — no valid NTP association needs to exist between attacker and target. Crypto-NAK packets from unknown/unassociated peers targeting ntpd should be treated as suspicious. ↗
- →The vulnerability was introduced specifically in ntp-4.2.8p7 (the fix for CVE-2016-1547 / NTP bug 3007). Systems running exactly 4.2.8p7 are the primary target; scan for this version in your environment. ↗
- ·Red Hat Enterprise Linux (versions 5, 6, and 7) are NOT affected because Red Hat's own fix for CVE-2016-1547 did not include the upstream change that introduced this bug. ↗
- ·The vulnerability cannot be escalated to remote code execution; impact is limited to denial of service (ntpd crash). ↗
- ·No workaround is available for affected systems; the only mitigation is patching to ntp-4.2.8p8 or later. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-16:24.ntp: Multiple vulnerabilities of ntp
bsd_advisories·2016-06-04·CVSS 7.5
CVE-2016-4953 [HIGH] FreeBSD-SA-16:24.ntp: Multiple vulnerabilities of ntp
FreeBSD-SA-16:24.ntp Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities of ntp
Category: contrib
Module: ntp
Announced: 2016-06-04
Credits: Network Time Foundation and various contributors listed below
Affects: All supported versions of FreeBSD.
Corrected: 2016-06-03 08:59:21 UTC (stable/10, 10.3-STABLE)
2016-06-04 05:46:52 UTC (releng/10.3, 10.3-RELEASE-p5)
2016-06-04 05:46:52 UTC (releng/10.2, 10.2-RELEASE-p19)
2016-06-04 05:46:52 UTC (releng/10.1, 10.1-RELEASE-p36)
2016-06-03 09:03:10 UTC (stable/9, 9.3-STABLE)
2016-06-04 05:46:52 UTC (releng/9.3, 9.3-RELEASE-p44)
CVE Name: CVE-2016-4957, CVE-2016-4953, CVE-2016-4954, CVE-2016-4955
CVE-2016-4956
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branc
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016
vendor_cisco·2016-06-03
CVE-2016-4953 [HIGH] Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016
Multiple Cisco products incorporate a version of the Network Time Protocol daemon (ntpd) package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or modify the time being advertised by a device acting as a Network Time Protocol (NTP) server.
On June 2, 2016, the NTP Consortium of the Network Time Foundation released a security notice that details five issues regarding DoS vulnerabilities and logic issues that may allow an attacker to shift a system's time.
The new vulnerabilities disclosed in this document are as follows:
Network Time Protocol CRYPTO-NAK Denial of Service Vuln
Red Hat
ntp: crypto-NAK DoS (incorrect fix for CVE-2016-1547)
vendor_redhat·2016-06-02·CVSS 5.3
CVE-2016-4957 [MEDIUM] ntp: crypto-NAK DoS (incorrect fix for CVE-2016-1547)
ntp: crypto-NAK DoS (incorrect fix for CVE-2016-1547)
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.
Statement: This issue did not affect the versions of ntp as shipped with any Red Hat Enterprise Linux version as they did not include the same upstream fix for CVE-2016-1547 that introduced the issue. The fix developed by Red Hat for CVE-2016-1547 did not include this issue.
Package: ntp (Red Hat Enterprise Linux 5) - Not affected
Package: ntp (Red Hat Enterprise Linux 6) - Not affected
Package: ntp (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2016-4957: ntp - ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service ...
vendor_debian·2016·CVSS 5.3
CVE-2016-4957 [MEDIUM] CVE-2016-4957: ntp - ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service ...
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p8+dfsg-1)
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016
vendor_cisco
CVE-2016-4957 Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016
CVE-2016-4957: Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016
Multiple Cisco products incorporate a version of the Network Time Protocol daemon (ntpd) package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or modify the time being advertised by a device acting as a Network Time Protocol (NTP) server. On June 2, 2016, the NTP Consortium of the Network Time Foundation released a security notice that
Bug IDs: CSCuz92606, CSCuz92609, CSCuz92629, CSCuz92606, CSCuz92609
GHSA
GHSA-3mq4-x52h-fcwc: ntpd in NTP before 4
ghsa_unreviewed·2022-05-13·CVSS 5.3
CVE-2016-4957 [MEDIUM] CWE-476 GHSA-3mq4-x52h-fcwc: ntpd in NTP before 4
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.
OSV
CVE-2016-4957: ntpd in NTP before 4
osv·2016-07-05·CVSS 5.3
CVE-2016-4957 [MEDIUM] CVE-2016-4957: ntpd in NTP before 4
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.
No detection rules found.
No public exploits indexed.
Fortinet
Analysis of Vulnerability CVE-2016-4957 in NTPD
blogs_fortinet·2016-06-20·CVSS 5.3
CVE-2016-4957 [MEDIUM] Analysis of Vulnerability CVE-2016-4957 in NTPD
FORTIGUARD LABS THREAT RESEARCH
Analysis of Vulnerability CVE-2016-4957 in NTPD
By Dehui Yin | June 20, 2016
The Network Time Protocol Daemon (NTPD) by NTP.org, runs on *nix operation systems. It sets and maintains system time in synchronization with internet standard time servers or local reference clocks. NTPD is shipped with many major server operating systems, routers, and infrastructure devices.
CVE-2016-4957 is a high severity vulnerability targeted at the NTPD. It causes a segfault event that causes NTPD to close. If the NTP service stops, it can affect many time-sensitive programs, such as database operations and server groups which need NTP to synchronize time with each other.
The ntp-4.2.8p8 update was released on Jun 02, 2016 to address this vulnerability, along with several
Bugzilla
CVE-2016-4957 ntp: crypto-NAK DoS (incorrect fix for CVE-2016-1547)
bugzilla·2016-05-30·CVSS 5.3
CVE-2016-4957 [MEDIUM] CVE-2016-4957 ntp: crypto-NAK DoS (incorrect fix for CVE-2016-1547)
CVE-2016-4957 ntp: crypto-NAK DoS (incorrect fix for CVE-2016-1547)
It was found that the fix for CVE-2016-1547 introduced a new issue. An attacker could send a crafted packet with crypto-NAK to a server or client that will cause ntpd to crash (segfault on NULL pointer dereference).
The issue was introduced in the original patch for CVE-2016-1547 here:
http://bk1.ntp.org/ntp-stable/?PAGE=patch&REV=56b42514rgZyUCPCWq2Uyhw4BWUpSg
Discussion:
Acknowledgments:
Name: CERT/CC
Upstream: Nicolas Edet (Cisco)
---
Statement:
This issue did not affect the versions of ntp as shipped with any Red Hat Enterprise Linux version as they did not include the same upstream fix for CVE-2016-1547 that introduced the issue. The fix developed by Red Hat for CVE-2016-1547 did not include this issue.
---
Bugzilla
CVE-2015-2181 CVE-2015-8864 CVE-2016-4068 CVE-2016-4069 roundcubemail: security issues fixed in version 1.0.9
bugzilla·2016-04-25·CVSS 8.8
CVE-2015-2181 [HIGH] CVE-2015-2181 CVE-2015-8864 CVE-2016-4068 CVE-2016-4069 roundcubemail: security issues fixed in version 1.0.9
CVE-2015-2181 CVE-2015-8864 CVE-2016-4068 CVE-2016-4069 roundcubemail: security issues fixed in version 1.0.9
Three issues were fixed in roundcubemail 1.0.9:
https://github.com/roundcube/roundcubemail/releases/tag/1.0.9
(CVE-2015-8864,CVE-2016-4068) Fix XSS issue in SVG images handling (#4949):
https://github.com/roundcube/roundcubemail/issues/4949
(CVE-2016-4069) Protect download urls against CSRF using unique request tokens (#4957):
https://github.com/roundcube/roundcubemail/issues/4957
(CVE-2015-2181) Fix (again) security issue in DBMail driver of password plugin (#4958):
https://github.com/roundcube/roundcubemail/issues/4958
Discussion:
Created roundcubemail tracking bugs for this issue:
Affects: fedora-all [bug 1330085]
Affects: epel-all [bug 1330086]
---
roundcubemail-1.
http://bugs.ntp.org/3046http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00040.htmlhttp://support.ntp.org/bin/view/Main/NtpBug3046http://support.ntp.org/bin/view/Main/SecurityNoticehttp://www.kb.cert.org/vuls/id/321640http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securitytracker.com/id/1036037https://security.FreeBSD.org/advisories/FreeBSD-SA-16:24.ntp.aschttps://security.gentoo.org/glsa/201607-15http://bugs.ntp.org/3046http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00040.htmlhttp://support.ntp.org/bin/view/Main/NtpBug3046http://support.ntp.org/bin/view/Main/SecurityNoticehttp://www.kb.cert.org/vuls/id/321640http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securitytracker.com/id/1036037https://security.FreeBSD.org/advisories/FreeBSD-SA-16:24.ntp.aschttps://security.gentoo.org/glsa/201607-15
2016-07-05
Published