CVE-2016-7433
published 2017-01-13CVE-2016-7433: NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to…
PriorityP337medium5.3CVSS 3.0
AVNACLPRNUINSUCNINAL
EPSS
9.84%
95.1th percentile
NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ntp | < ntp 1:4.2.8p9+dfsg-1 (bullseye) | ntp 1:4.2.8p9+dfsg-1 (bullseye) |
| ntp | ntp | <= 4.2.8 | — |
| ntp | ntp | >= 0 < 1:4.2.8p9+dfsg-1 | 1:4.2.8p9+dfsg-1 |
| ntp | ntp | >= 0 < 1:4.2.6.p5+dfsg-3ubuntu2.14.04.11 | 1:4.2.6.p5+dfsg-3ubuntu2.14.04.11 |
| ntp | ntp | >= 0 < 1:4.2.8p4+dfsg-3ubuntu5.5 | 1:4.2.8p4+dfsg-3ubuntu5.5 |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_ubuntu5.9MEDIUM
vendor_cisco5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5x79-wfvw-985r: NTP before 4
ghsa_unreviewed·2022-05-13
CVE-2016-7433 [MEDIUM] CWE-682 GHSA-5x79-wfvw-985r: NTP before 4
NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."
OSV
ntp vulnerabilities
osv·2017-07-05·CVSS 5.9
CVE-2016-2519 [MEDIUM] ntp vulnerabilities
ntp vulnerabilities
Yihan Lian discovered that NTP incorrectly handled certain large request
data values. A remote attacker could possibly use this issue to cause NTP
to crash, resulting in a denial of service. This issue only affected
Ubuntu 16.04 LTS. (CVE-2016-2519)
Miroslav Lichvar discovered that NTP incorrectly handled certain spoofed
addresses when performing rate limiting. A remote attacker could possibly
use this issue to perform a denial of service. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 16.10. (CVE-2016-7426)
Matthew Van Gundy discovered that NTP incorrectly handled certain crafted
broadcast mode packets. A remote attacker could possibly use this issue to
perform a denial of service. This issue only affected Ubuntu 14.04 LTS,
Ubuntu 16.04 LTS,
OSV
CVE-2016-7433: NTP before 4
osv·2017-01-13·CVSS 5.3
CVE-2016-7433 [MEDIUM] CVE-2016-7433: NTP before 4
NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."
CISA ICS
Siemens SIMATIC NET CP 443-1 OPC UA
cisa_ics·2021-06-08·CVSS 5.9
[MEDIUM] Siemens SIMATIC NET CP 443-1 OPC UA
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC NET CP 443-1 OPC UA
Last RevisedJune 08, 2021
Alert CodeICSA-21-159-11
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC NET CP 443-1 OPC UA
- Vulnerabilities: Improper Input Validation, Improper Restriction of Operations within the Bounds of a Memory Buffer, Incorrect Calculation, Classic Buffer Overflow, Improper Authentication, Race Condition, Data Processing Errors, Exposure of Sensitive Information to an Unauthorized Actor, Out-of-bounds Read
## 2. RISK EVALUATION
Succes
Ubuntu
NTP vulnerabilities
vendor_ubuntu·2017-07-05·CVSS 5.9
CVE-2016-2519 [MEDIUM] NTP vulnerabilities
Title: NTP vulnerabilities
Summary: Several security issues were fixed in NTP.
Yihan Lian discovered that NTP incorrectly handled certain large request
data values. A remote attacker could possibly use this issue to cause NTP
to crash, resulting in a denial of service. This issue only affected
Ubuntu 16.04 LTS. (CVE-2016-2519)
Miroslav Lichvar discovered that NTP incorrectly handled certain spoofed
addresses when performing rate limiting. A remote attacker could possibly
use this issue to perform a denial of service. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 16.10. (CVE-2016-7426)
Matthew Van Gundy discovered that NTP incorrectly handled certain crafted
broadcast mode packets. A remote attacker could possibly use this issue to
perform a denial of service.
BSD
FreeBSD-SA-16:39.ntp: Multiple vulnerabilities of ntp
bsd_advisories·2016-12-22·CVSS 7.5
CVE-2016-7426 [HIGH] FreeBSD-SA-16:39.ntp: Multiple vulnerabilities of ntp
FreeBSD-SA-16:39.ntp Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities of ntp
Category: contrib
Module: ntp
Announced: 2016-12-22
Credits: Network Time Foundation
Affects: All supported versions of FreeBSD.
Corrected: 2016-11-22 16:22:51 UTC (stable/11, 11.0-STABLE)
2016-12-22 16:19:05 UTC (releng/11.0, 11.0-RELEASE-p6)
2016-11-22 16:23:20 UTC (stable/10, 10.3-STABLE)
2016-12-22 16:19:05 UTC (releng/10.3, 10.3-RELEASE-p15)
2016-12-22 16:19:05 UTC (releng/10.2, 10.2-RELEASE-p28)
2016-12-22 16:19:05 UTC (releng/10.1, 10.1-RELEASE-p45)
2016-11-22 16:23:46 UTC (stable/9, 9.3-STABLE)
2016-12-22 16:19:05 UTC (releng/9.3, 9.3-RELEASE-p53)
CVE Name: CVE-2016-7426, CVE-2016-7427, CVE-2016-7428, CVE-2016-7431,
CVE-2016-7433, CVE-2016-7434, CVE-2016-9310, CVE-2016-9311
For gene
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: November 2016
vendor_cisco·2016-11-23·CVSS 5.3
CVE-2015-8138 [MEDIUM] CWE-119 Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: November 2016
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: November 2016
Multiple Cisco products incorporate a version of the Network Time Protocol daemon (ntpd) package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or modify the time being advertised by a device acting as a Network Time Protocol (NTP) server.
On November 21, 2016, the NTP Consortium of the Network Time Foundation released a security notice that details ten issues regarding DoS vulnerabilities and logic issues that may allow an attacker to shift a system's time.
The new vulnerabilities disclosed in this document are as follows:
Network Time Protocol Trap Service Denial of S
Red Hat
ntp: Broken initial sync calculations regression
vendor_redhat·2016-11-21·CVSS 5.3
CVE-2016-7433 [MEDIUM] CWE-682 ntp: Broken initial sync calculations regression
ntp: Broken initial sync calculations regression
NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."
A flaw was found in the way ntpd calculated the root delay. A remote attacker could send a specially-crafted spoofed packet to cause denial of service or in some special cases even crash.
Package: ntp (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2016-7433: ntp - NTP before 4.2.8p9 does not properly perform the initial sync calculations, whic...
vendor_debian·2016·CVSS 5.3
CVE-2016-7433 [MEDIUM] CVE-2016-7433: ntp - NTP before 4.2.8p9 does not properly perform the initial sync calculations, whic...
NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."
Scope: local
bullseye: resolved (fixed in 1:4.2.8p9+dfsg-1)
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: November 2016
vendor_cisco
CVE-2016-7433 Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: November 2016
CVE-2016-7433: Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: November 2016
Multiple Cisco products incorporate a version of the Network Time Protocol daemon (ntpd) package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or modify the time being advertised by a device acting as a Network Time Protocol (NTP) server. On November 21, 2016, the NTP Consortium of the Network Time Foundation released a security notice that
CWE: CWE-119, CWE-20, CWE-399, CWE-119, CWE-20, CWE-399
Bug IDs: CSCvc22942, CSCvc23435, CSCvc23437, CSCvc22942, CSCvc23435
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-7433 ntp: Broken initial sync calculations regression
bugzilla·2016-11-22·CVSS 5.3
CVE-2016-7433 [MEDIUM] CVE-2016-7433 ntp: Broken initial sync calculations regression
CVE-2016-7433 ntp: Broken initial sync calculations regression
Bug 2085 described a condition where the root delay was included twice, causing the jitter value to be higher than expected. Due to a misinterpretation of a small-print variable in The Book, the fix for this problem was incorrect, resulting in a root distance that did not include the peer dispersion. The calculations and formulae have been reviewed and reconciled, and the code has been updated accordingly.
External References:
http://support.ntp.org/bin/view/Main/NtpBug3067
Discussion:
Created ntp tracking bugs for this issue:
Affects: fedora-all [bug 1397351]
---
Analysis:
When an offpath attacker can spoof the first ntp reply, ntpd will jump and when it gets a real response, it will exit.
---
Is an RPM released wit
Bugzilla
CVE-2016-7426 CVE-2016-7429 CVE-2016-7433 CVE-2016-9310 CVE-2016-9311 ntp: various flaws [fedora-all]
bugzilla·2016-11-22·CVSS 7.5
CVE-2016-7426 [HIGH] CVE-2016-7426 CVE-2016-7429 CVE-2016-7433 CVE-2016-9310 CVE-2016-9311 ntp: various flaws [fedora-all]
CVE-2016-7426 CVE-2016-7429 CVE-2016-7433 CVE-2016-9310 CVE-2016-9311 ntp: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
http://lists.opensuse.org/opensuse-updates/2016-12/msg00153.htmlhttp://nwtime.org/ntp428p9_release/http://rhn.redhat.com/errata/RHSA-2017-0252.htmlhttp://support.ntp.org/bin/view/Main/NtpBug3067http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_Vulnerabilitieshttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171129-01-ntpd-enhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/archive/1/539955/100/0/threadedhttp://www.securityfocus.com/archive/1/540254/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/539955/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/540254/100/0/threadedhttp://www.securityfocus.com/bid/94455http://www.securitytracker.com/id/1037354http://www.ubuntu.com/usn/USN-3349-1https://bto.bluecoat.com/security-advisory/sa139https://cert-portal.siemens.com/productcert/pdf/ssa-211752.pdfhttps://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03706en_ushttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ILMSYVQMMF37MANYEO7KBHOPSC74EKGN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PABKEYX6ABBFJZGMXKH57X756EJUDS3C/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U5E3XBBCK5IXOLDAH2E4M3QKIYIHUMMP/https://security.FreeBSD.org/advisories/FreeBSD-SA-16:39.ntp.aschttps://us-cert.cisa.gov/ics/advisories/icsa-21-159-11https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-227https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-227/https://www.kb.cert.org/vuls/id/633847http://lists.opensuse.org/opensuse-updates/2016-12/msg00153.htmlhttp://nwtime.org/ntp428p9_release/http://rhn.redhat.com/errata/RHSA-2017-0252.htmlhttp://support.ntp.org/bin/view/Main/NtpBug3067http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_Vulnerabilitieshttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171129-01-ntpd-enhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/archive/1/539955/100/0/threadedhttp://www.securityfocus.com/archive/1/540254/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/539955/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/540254/100/0/threadedhttp://www.securityfocus.com/bid/94455http://www.securitytracker.com/id/1037354http://www.ubuntu.com/usn/USN-3349-1https://bto.bluecoat.com/security-advisory/sa139https://cert-portal.siemens.com/productcert/pdf/ssa-211752.pdfhttps://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03706en_ushttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ILMSYVQMMF37MANYEO7KBHOPSC74EKGN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PABKEYX6ABBFJZGMXKH57X756EJUDS3C/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U5E3XBBCK5IXOLDAH2E4M3QKIYIHUMMP/https://security.FreeBSD.org/advisories/FreeBSD-SA-16:39.ntp.aschttps://us-cert.cisa.gov/ics/advisories/icsa-21-159-11https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-227https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-227/https://www.kb.cert.org/vuls/id/633847
2017-01-13
Published