CVE-2016-9042
published 2018-06-04CVE-2016-9042: An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network…
PriorityP433medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
3.96%
89.3th percentile
An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_high_sierra | — | — |
| debian | ntp | < ntp 1:4.2.8p10+dfsg-1 (bullseye) | ntp 1:4.2.8p10+dfsg-1 (bullseye) |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| hpe | hpux-ntp | < c.4.2.8.4.0 | c.4.2.8.4.0 |
| ntp | ntp | — | — |
| ntp | ntp | >= 0 < 1:4.2.8p10+dfsg-1 | 1:4.2.8p10+dfsg-1 |
| ntp | ntp | >= 0 < 1:4.2.6.p5+dfsg-3ubuntu2.14.04.11 | 1:4.2.6.p5+dfsg-3ubuntu2.14.04.11 |
| ntp | ntp | >= 0 < 1:4.2.8p4+dfsg-3ubuntu5.5 | 1:4.2.8p4+dfsg-3ubuntu5.5 |
| talos | network_time_protocol | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.03.7LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7wvh-qg35-v45r: An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4
ghsa_unreviewed·2022-05-13
CVE-2016-9042 [MEDIUM] CWE-20 GHSA-7wvh-qg35-v45r: An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4
An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.
OSV
CVE-2016-9042: An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4
osv·2018-06-04·CVSS 5.9
CVE-2016-9042 [MEDIUM] CVE-2016-9042: An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4
An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.
OSV
ntp vulnerabilities
osv·2017-07-05·CVSS 5.9
CVE-2016-2519 [MEDIUM] ntp vulnerabilities
ntp vulnerabilities
Yihan Lian discovered that NTP incorrectly handled certain large request
data values. A remote attacker could possibly use this issue to cause NTP
to crash, resulting in a denial of service. This issue only affected
Ubuntu 16.04 LTS. (CVE-2016-2519)
Miroslav Lichvar discovered that NTP incorrectly handled certain spoofed
addresses when performing rate limiting. A remote attacker could possibly
use this issue to perform a denial of service. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 16.10. (CVE-2016-7426)
Matthew Van Gundy discovered that NTP incorrectly handled certain crafted
broadcast mode packets. A remote attacker could possibly use this issue to
perform a denial of service. This issue only affected Ubuntu 14.04 LTS,
Ubuntu 16.04 LTS,
CISA ICS
Siemens SIMATIC NET CP 443-1 OPC UA
cisa_ics·2021-06-08·CVSS 5.9
[MEDIUM] Siemens SIMATIC NET CP 443-1 OPC UA
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC NET CP 443-1 OPC UA
Last RevisedJune 08, 2021
Alert CodeICSA-21-159-11
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC NET CP 443-1 OPC UA
- Vulnerabilities: Improper Input Validation, Improper Restriction of Operations within the Bounds of a Memory Buffer, Incorrect Calculation, Classic Buffer Overflow, Improper Authentication, Race Condition, Data Processing Errors, Exposure of Sensitive Information to an Unauthorized Actor, Out-of-bounds Read
## 2. RISK EVALUATION
Succes
Apple
CVE-2016-9042: macOS High Sierra 10.13
vendor_apple·2017-09-25·CVSS 5.9
CVE-2016-9042 [MEDIUM] CVE-2016-9042: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2016-9042
Component: Mail Drafts
Impact: An attacker with a privileged network position may be able to intercept mail contents
Description: An encryption issue existed in the handling of mail drafts. This issue was addressed with improved handling of mail drafts meant to be sent encrypted.
Ubuntu
NTP vulnerabilities
vendor_ubuntu·2017-07-05·CVSS 5.9
CVE-2016-2519 [MEDIUM] NTP vulnerabilities
Title: NTP vulnerabilities
Summary: Several security issues were fixed in NTP.
Yihan Lian discovered that NTP incorrectly handled certain large request
data values. A remote attacker could possibly use this issue to cause NTP
to crash, resulting in a denial of service. This issue only affected
Ubuntu 16.04 LTS. (CVE-2016-2519)
Miroslav Lichvar discovered that NTP incorrectly handled certain spoofed
addresses when performing rate limiting. A remote attacker could possibly
use this issue to perform a denial of service. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 16.10. (CVE-2016-7426)
Matthew Van Gundy discovered that NTP incorrectly handled certain crafted
broadcast mode packets. A remote attacker could possibly use this issue to
perform a denial of service.
BSD
FreeBSD-SA-17:03.ntp: Multiple vulnerabilities of ntp
bsd_advisories·2017-04-12·CVSS 5.9
CVE-2016-9042 [MEDIUM] FreeBSD-SA-17:03.ntp: Multiple vulnerabilities of ntp
FreeBSD-SA-17:03.ntp Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities of ntp
Category: contrib
Module: ntp
Announced: 2017-04-12
Credits: Network Time Foundation
Affects: All supported versions of FreeBSD.
Corrected: 2017-03-28 04:48:17 UTC (stable/11, 11.0-STABLE)
2017-04-12 06:24:35 UTC (releng/11.0, 11.0-RELEASE-p9)
2017-03-28 04:48:55 UTC (stable/10, 10.3-STABLE)
2017-04-12 06:24:35 UTC (releng/10.3, 10.3-RELEASE-p18)
CVE Name: CVE-2017-6464, CVE-2017-6462, CVE-2017-6463, CVE-2016-9042
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
The ntpd(8) daemon is an implementation of the Network Time Protocol (NTP)
used to synchronize t
Red Hat
ntp: DoS via origin timestamp check functionality
vendor_redhat·2017-03-21·CVSS 5.9
CVE-2016-9042 [MEDIUM] CWE-20 ntp: DoS via origin timestamp check functionality
ntp: DoS via origin timestamp check functionality
An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.
A vulnerability was found in NTP, affecting the origin timestamp check function. An attacker able to spoof messages from all of the configured peers could send crafted packets to ntpd, causing later replies from those peers to be discarded, resulting in denial of service.
Mitigation: Implement BCP-38.
Configure enough servers/peers that an attacker c
Debian
CVE-2016-9042: ntp - An exploitable denial of service vulnerability exists in the origin timestamp ch...
vendor_debian·2016·CVSS 5.9
CVE-2016-9042 [MEDIUM] CVE-2016-9042: ntp - An exploitable denial of service vulnerability exists in the origin timestamp ch...
An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p10+dfsg-1)
No detection rules found.
No public exploits indexed.
http://packetstormsecurity.com/files/142101/FreeBSD-Security-Advisory-FreeBSD-SA-17-03.ntp.htmlhttp://packetstormsecurity.com/files/142284/Slackware-Security-Advisory-ntp-Updates.htmlhttp://seclists.org/fulldisclosure/2017/Nov/7http://seclists.org/fulldisclosure/2017/Sep/62http://www.securityfocus.com/archive/1/540403/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/540403/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/540464/100/0/threadedhttp://www.securityfocus.com/bid/97046http://www.securitytracker.com/id/1038123http://www.securitytracker.com/id/1039427http://www.ubuntu.com/usn/USN-3349-1https://bto.bluecoat.com/security-advisory/sa147https://cert-portal.siemens.com/productcert/pdf/ssa-211752.pdfhttps://kc.mcafee.com/corporate/index?page=content&id=SB10201https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7KVLFA3J43QFIP4I7HE7KQ5FXSMJEKC6/https://security.FreeBSD.org/advisories/FreeBSD-SA-17:03.ntp.aschttps://support.apple.com/kb/HT208144https://support.f5.com/csp/article/K39041624https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_ushttps://us-cert.cisa.gov/ics/advisories/icsa-21-159-11https://www.talosintelligence.com/vulnerability_reports/TALOS-2016-0260http://packetstormsecurity.com/files/142101/FreeBSD-Security-Advisory-FreeBSD-SA-17-03.ntp.htmlhttp://packetstormsecurity.com/files/142284/Slackware-Security-Advisory-ntp-Updates.htmlhttp://seclists.org/fulldisclosure/2017/Nov/7http://seclists.org/fulldisclosure/2017/Sep/62http://www.securityfocus.com/archive/1/540403/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/540403/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/540464/100/0/threadedhttp://www.securityfocus.com/bid/97046http://www.securitytracker.com/id/1038123http://www.securitytracker.com/id/1039427http://www.ubuntu.com/usn/USN-3349-1https://bto.bluecoat.com/security-advisory/sa147https://cert-portal.siemens.com/productcert/pdf/ssa-211752.pdfhttps://kc.mcafee.com/corporate/index?page=content&id=SB10201https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7KVLFA3J43QFIP4I7HE7KQ5FXSMJEKC6/https://security.FreeBSD.org/advisories/FreeBSD-SA-17:03.ntp.aschttps://support.apple.com/kb/HT208144https://support.f5.com/csp/article/K39041624https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_ushttps://us-cert.cisa.gov/ics/advisories/icsa-21-159-11https://www.talosintelligence.com/vulnerability_reports/TALOS-2016-0260
2018-06-04
Published