CVE-2016-7429Improper Restriction of Operations within the Bounds of a Memory Buffer in NTP

Severity
3.7LOWNVD
OSV5.9
EPSS
5.2%
top 10.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 13
Latest updateMay 14

Description

NTP before 4.2.8p9 changes the peer structure to the interface it receives the response from a source, which allows remote attackers to cause a denial of service (prevent communication with a source) by sending a response for a source to an interface the source does not use.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 2.2 | Impact: 1.4

Affected Packages4 packages

debiandebian/ntp< ntp 1:4.2.8p9+dfsg-1 (bullseye)
Debianntp/ntp< 1:4.2.8p9+dfsg-1
Ubuntuntp/ntp< 1:4.2.6.p5+dfsg-3ubuntu2.14.04.11+1
NVDntp/ntp4.2.8

🔴Vulnerability Details

3
GHSA
GHSA-9h42-3m2m-9456: NTP before 42022-05-14
OSV
ntp vulnerabilities2017-07-05
OSV
CVE-2016-7429: NTP before 42017-01-13

📋Vendor Advisories

5
Ubuntu
NTP vulnerabilities2017-07-05
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: November 20162016-11-23
Red Hat
ntp: Attack on interface selection2016-11-21
Debian
CVE-2016-7429: ntp - NTP before 4.2.8p9 changes the peer structure to the interface it receives the r...2016
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: November 2016

💬Community

2
Bugzilla
CVE-2016-7426 CVE-2016-7429 CVE-2016-7433 CVE-2016-9310 CVE-2016-9311 ntp: various flaws [fedora-all]2016-11-22
Bugzilla
CVE-2016-7429 ntp: Attack on interface selection2016-11-22