CVE-2017-6464
published 2017-03-27CVE-2017-6464: NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote attackers to cause a denial of service (ntpd crash) via a malformed mode configuration directive.
PriorityP431medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
5.10%
91.5th percentile
NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote attackers to cause a denial of service (ntpd crash) via a malformed mode configuration directive.
Affected
100 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_high_sierra | — | — |
| debian | ntp | < ntp 1:4.2.8p10+dfsg-1 (bullseye) | ntp 1:4.2.8p10+dfsg-1 (bullseye) |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x7p4-m2g6-wmgc: NTP before 4
ghsa_unreviewed·2022-05-14
CVE-2017-6464 [MEDIUM] CWE-20 GHSA-x7p4-m2g6-wmgc: NTP before 4
NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote attackers to cause a denial of service (ntpd crash) via a malformed mode configuration directive.
OSV
ntp vulnerabilities
osv·2017-07-05·CVSS 5.9
CVE-2016-2519 [MEDIUM] ntp vulnerabilities
ntp vulnerabilities
Yihan Lian discovered that NTP incorrectly handled certain large request
data values. A remote attacker could possibly use this issue to cause NTP
to crash, resulting in a denial of service. This issue only affected
Ubuntu 16.04 LTS. (CVE-2016-2519)
Miroslav Lichvar discovered that NTP incorrectly handled certain spoofed
addresses when performing rate limiting. A remote attacker could possibly
use this issue to perform a denial of service. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 16.10. (CVE-2016-7426)
Matthew Van Gundy discovered that NTP incorrectly handled certain crafted
broadcast mode packets. A remote attacker could possibly use this issue to
perform a denial of service. This issue only affected Ubuntu 14.04 LTS,
Ubuntu 16.04 LTS,
OSV
CVE-2017-6464: NTP before 4
osv·2017-03-27·CVSS 6.5
CVE-2017-6464 [MEDIUM] CVE-2017-6464: NTP before 4
NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote attackers to cause a denial of service (ntpd crash) via a malformed mode configuration directive.
Apple
CVE-2017-6464: macOS High Sierra 10.13
vendor_apple·2017-09-25·CVSS 6.5
CVE-2017-6464 [MEDIUM] CVE-2017-6464: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-6464
Component: Mail Drafts
Impact: An attacker with a privileged network position may be able to intercept mail contents
Description: An encryption issue existed in the handling of mail drafts. This issue was addressed with improved handling of mail drafts meant to be sent encrypted.
Ubuntu
NTP vulnerabilities
vendor_ubuntu·2017-07-05·CVSS 5.9
CVE-2016-2519 [MEDIUM] NTP vulnerabilities
Title: NTP vulnerabilities
Summary: Several security issues were fixed in NTP.
Yihan Lian discovered that NTP incorrectly handled certain large request
data values. A remote attacker could possibly use this issue to cause NTP
to crash, resulting in a denial of service. This issue only affected
Ubuntu 16.04 LTS. (CVE-2016-2519)
Miroslav Lichvar discovered that NTP incorrectly handled certain spoofed
addresses when performing rate limiting. A remote attacker could possibly
use this issue to perform a denial of service. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 16.10. (CVE-2016-7426)
Matthew Van Gundy discovered that NTP incorrectly handled certain crafted
broadcast mode packets. A remote attacker could possibly use this issue to
perform a denial of service.
BSD
FreeBSD-SA-17:03.ntp: Multiple vulnerabilities of ntp
bsd_advisories·2017-04-12·CVSS 5.9
CVE-2016-9042 [MEDIUM] FreeBSD-SA-17:03.ntp: Multiple vulnerabilities of ntp
FreeBSD-SA-17:03.ntp Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities of ntp
Category: contrib
Module: ntp
Announced: 2017-04-12
Credits: Network Time Foundation
Affects: All supported versions of FreeBSD.
Corrected: 2017-03-28 04:48:17 UTC (stable/11, 11.0-STABLE)
2017-04-12 06:24:35 UTC (releng/11.0, 11.0-RELEASE-p9)
2017-03-28 04:48:55 UTC (stable/10, 10.3-STABLE)
2017-04-12 06:24:35 UTC (releng/10.3, 10.3-RELEASE-p18)
CVE Name: CVE-2017-6464, CVE-2017-6462, CVE-2017-6463, CVE-2016-9042
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
The ntpd(8) daemon is an implementation of the Network Time Protocol (NTP)
used to synchronize t
Red Hat
ntp: Denial of Service via Malformed Config
vendor_redhat·2017-03-21·CVSS 6.5
CVE-2017-6464 [MEDIUM] CWE-20 ntp: Denial of Service via Malformed Config
ntp: Denial of Service via Malformed Config
NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote attackers to cause a denial of service (ntpd crash) via a malformed mode configuration directive.
A vulnerability was discovered in the NTP server's parsing of configuration directives. A remote, authenticated attacker could cause ntpd to crash by sending a crafted message.
Mitigation: Properly monitor your ntpd instances, and auto-restart ntpd (without -g) if it stops running.
Package: ntp (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2017-6464: ntp - NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote attackers to cause a d...
vendor_debian·2017·CVSS 6.5
CVE-2017-6464 [MEDIUM] CVE-2017-6464: ntp - NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote attackers to cause a d...
NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote attackers to cause a denial of service (ntpd crash) via a malformed mode configuration directive.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p10+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-6464 CVE-2017-6462 CVE-2017-6463 CVE-2017-6458 CVE-2017-6451 ntp: various flaws [fedora-all]
bugzilla·2017-03-23·CVSS 7.8
CVE-2017-6464 [HIGH] CVE-2017-6464 CVE-2017-6462 CVE-2017-6463 CVE-2017-6458 CVE-2017-6451 ntp: various flaws [fedora-all]
CVE-2017-6464 CVE-2017-6462 CVE-2017-6463 CVE-2017-6458 CVE-2017-6451 ntp: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2017-6464 ntp: Denial of Service via Malformed Config
bugzilla·2017-03-20·CVSS 6.5
CVE-2017-6464 [MEDIUM] CVE-2017-6464 ntp: Denial of Service via Malformed Config
CVE-2017-6464 ntp: Denial of Service via Malformed Config
A vulnerability found in the NTP server makes it possible for an authenticated remote user to crash ntpd via a malformed mode configuration directive.
Mitigation:
Properly monitor your ntpd instances, and auto-restart ntpd (without -g) if it stops running.
Discussion:
Acknowledgments:
Name: the NTP project
Upstream: Cure53
---
Created ntp tracking bugs for this issue:
Affects: fedora-all [bug 1435163]
---
In ntp-4.2.6p5 and ntp-4.2.4p8, the ttl value is an unsigned char (rather than uint32), limiting the OOB read to a (256-8)-byte region. Testing on x86_64 fails to cause a crash.
Different compiler or linker options, or different hardware, could still result in a crash being possible through this vector.
---
Is RHEL-7
http://support.ntp.org/bin/view/Main/NtpBug3389http://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_Secuhttp://www.securityfocus.com/bid/97050http://www.securitytracker.com/id/1038123https://access.redhat.com/errata/RHSA-2017:3071https://access.redhat.com/errata/RHSA-2018:0855https://security.FreeBSD.org/advisories/FreeBSD-SA-17:03.ntp.aschttps://support.apple.com/HT208144https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_ushttp://support.ntp.org/bin/view/Main/NtpBug3389http://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_Secuhttp://www.securityfocus.com/bid/97050http://www.securitytracker.com/id/1038123https://access.redhat.com/errata/RHSA-2017:3071https://access.redhat.com/errata/RHSA-2018:0855https://security.FreeBSD.org/advisories/FreeBSD-SA-17:03.ntp.aschttps://support.apple.com/HT208144https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_us
2017-03-27
Published