CVE-2016-6301
published 2016-12-09CVE-2016-6301: The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth consumption)…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
8.89%
94.6th percentile
The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged NTP packet, which triggers a communication loop.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| busybox | busybox | < 1.25.1 | 1.25.1 |
| busybox | busybox | >= 0 < 1:1.27.2-1 | 1:1.27.2-1 |
| busybox | busybox | >= 0 < 1:1.27.2-1 | 1:1.27.2-1 |
| busybox | busybox | >= 0 < 1:1.27.2-1 | 1:1.27.2-1 |
| busybox | busybox | >= 0 < 1:1.27.2-1 | 1:1.27.2-1 |
| debian | busybox | < busybox 1:1.27.2-1 (bookworm) | busybox 1:1.27.2-1 (bookworm) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ww72-35h4-5v84: The recv_and_process_client_pkt function in networking/ntpd
ghsa_unreviewed·2022-05-13
CVE-2016-6301 [HIGH] CWE-835 GHSA-ww72-35h4-5v84: The recv_and_process_client_pkt function in networking/ntpd
The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged NTP packet, which triggers a communication loop.
OSV
CVE-2016-6301: The recv_and_process_client_pkt function in networking/ntpd
osv·2016-12-09·CVSS 7.5
CVE-2016-6301 [HIGH] CVE-2016-6301: The recv_and_process_client_pkt function in networking/ntpd
The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged NTP packet, which triggers a communication loop.
CISA ICS
Advantech Spectre RT Industrial Routers
cisa_ics·2021-02-23·CVSS 7.5
[HIGH] Advantech Spectre RT Industrial Routers
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Advantech Spectre RT Industrial Routers
Last RevisedFebruary 23, 2021
Alert CodeICSA-21-054-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 10.0
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Advantech
- Equipment: Spectre RT Industrial Routers
- Vulnerabilities: Improper Neutralization of Input During Web Page Generation, Cleartext Transmission of Sensitive Information, Improper Restriction of Excessive Authentication Attempts, Use of a Broken or Risky Cryptographic Algorithm, Use of Platform-Dependent Third-party Components
## 2. RISK EVALUATION
Successful e
Red Hat
busybox: NTP server denial of service flaw
vendor_redhat·2016-08-03·CVSS 7.5
CVE-2016-6301 [HIGH] busybox: NTP server denial of service flaw
busybox: NTP server denial of service flaw
The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged NTP packet, which triggers a communication loop.
Package: busybox (Red Hat Enterprise Linux 5) - Will not fix
Package: busybox (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2016-6301: busybox - The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows ...
vendor_debian·2016·CVSS 7.5
CVE-2016-6301 [HIGH] CVE-2016-6301: busybox - The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows ...
The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged NTP packet, which triggers a communication loop.
Scope: local
bookworm: resolved (fixed in 1:1.27.2-1)
bullseye: resolved (fixed in 1:1.27.2-1)
forky: resolved (fixed in 1:1.27.2-1)
sid: resolved (fixed in 1:1.27.2-1)
trixie: resolved (fixed in 1:1.27.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6301 busybox: NTP server denial of service flaw
bugzilla·2016-08-03·CVSS 7.5
CVE-2016-6301 [HIGH] CVE-2016-6301 busybox: NTP server denial of service flaw
CVE-2016-6301 busybox: NTP server denial of service flaw
The busybox NTP implementation doesn't check the NTP mode of packets received on the server port and responds to any packet with the right size. This includes responses from another NTP server. An attacker can send a packet with a spoofed source address in order to create an infinite loop of responses between two busybox NTP servers. Adding more packets to the loop increases the traffic between the servers until one of them has a fully loaded CPU and/or network.
It seems this bug was actually inherited from openntpd, on which the busybox implementation was based on. In openntpd it was fixed in:
https://github.com/openntpd-portable/openntpd-openbsd/commit/28a2f904aafbf4c209fe6fa04ffb9308740fd78a
Busybox upstream patch:
https://gi
Bugzilla
CVE-2016-6301 busybox: NTP server denial of service flaw [fedora-all]
bugzilla·2016-08-03·CVSS 7.5
CVE-2016-6301 [HIGH] CVE-2016-6301 busybox: NTP server denial of service flaw [fedora-all]
CVE-2016-6301 busybox: NTP server denial of service flaw [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
http://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.htmlhttp://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.htmlhttp://seclists.org/fulldisclosure/2019/Jun/18http://seclists.org/fulldisclosure/2019/Sep/7http://seclists.org/fulldisclosure/2020/Aug/20http://seclists.org/fulldisclosure/2020/Mar/15http://www.openwall.com/lists/oss-security/2016/08/03/7http://www.securityfocus.com/bid/92277https://bugzilla.redhat.com/show_bug.cgi?id=1363710https://git.busybox.net/busybox/commit/?id=150dc7a2b483b8338a3e185c478b4b23ee884e71https://seclists.org/bugtraq/2019/Jun/14https://seclists.org/bugtraq/2019/Sep/7https://security.gentoo.org/glsa/201701-05http://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.htmlhttp://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.htmlhttp://seclists.org/fulldisclosure/2019/Jun/18http://seclists.org/fulldisclosure/2019/Sep/7http://seclists.org/fulldisclosure/2020/Aug/20http://seclists.org/fulldisclosure/2020/Mar/15http://www.openwall.com/lists/oss-security/2016/08/03/7http://www.securityfocus.com/bid/92277https://bugzilla.redhat.com/show_bug.cgi?id=1363710https://git.busybox.net/busybox/commit/?id=150dc7a2b483b8338a3e185c478b4b23ee884e71https://seclists.org/bugtraq/2019/Jun/14https://seclists.org/bugtraq/2019/Sep/7https://security.gentoo.org/glsa/201701-05
2016-12-09
Published