CVE-2016-7429 — Improper Restriction of Operations within the Bounds of a Memory Buffer in NTP
Severity
3.7LOWNVD
OSV5.9
EPSS
5.2%
top 10.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 13
Latest updateMay 14
Description
NTP before 4.2.8p9 changes the peer structure to the interface it receives the response from a source, which allows remote attackers to cause a denial of service (prevent communication with a source) by sending a response for a source to an interface the source does not use.
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 2.2 | Impact: 1.4
Affected Packages4 packages
🔴Vulnerability Details
3📋Vendor Advisories
5Cisco▶
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: November 2016↗2016-11-23
Debian▶
CVE-2016-7429: ntp - NTP before 4.2.8p9 changes the peer structure to the interface it receives the r...↗2016
Cisco▶
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: November 2016↗