cbcvebase.
CVE-2016-7426
published 2017-01-13

CVE-2016-7426: NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debianntp< ntp 1:4.2.8p9+dfsg-1 (bullseye)ntp 1:4.2.8p9+dfsg-1 (bullseye)
hpehpux-ntp>= b.11.31 < c.4.2.8.2.0c.4.2.8.2.0
ntpntp
ntpntp
ntpntp>= 0 < 1:4.2.8p9+dfsg-11:4.2.8p9+dfsg-1
ntpntp>= 0 < 1:4.2.6.p5+dfsg-3ubuntu2.14.04.111:4.2.6.p5+dfsg-3ubuntu2.14.04.11
ntpntp>= 0 < 1:4.2.8p4+dfsg-3ubuntu5.51:4.2.8p4+dfsg-3ubuntu5.5
ntpntp>= 4.2.6 < 4.2.84.2.8
ntpntp>= 4.3.0 < 4.3.944.3.94
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH