CVE-2018-8956
published 2020-05-06CVE-2018-8956: ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP…
PriorityP433medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
3.04%
86.1th percentile
ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via soofed mode 3 and mode 5 packets. The attacker must either be a part of the same broadcast network or control a slave in that broadcast network that can capture certain required packets on the attacker's behalf and send them to the attacker.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ntp | < ntp 1:4.2.8p14+dfsg-1 (bullseye) | ntp 1:4.2.8p14+dfsg-1 (bullseye) |
| debian | ntpsec | < ntp 1:4.2.8p14+dfsg-1 (bullseye) | ntp 1:4.2.8p14+dfsg-1 (bullseye) |
| ntp | ntp | — | — |
| ntp | ntp | >= 0 < 1:4.2.8p14+dfsg-1 | 1:4.2.8p14+dfsg-1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gg7p-jc5w-p68m: ntpd in ntp 4
ghsa_unreviewed·2022-05-24
CVE-2018-8956 [MEDIUM] GHSA-gg7p-jc5w-p68m: ntpd in ntp 4
ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via soofed mode 3 and mode 5 packets. The attacker must either be a part of the same broadcast network or control a slave in that broadcast network that can capture certain required packets on the attacker's behalf and send them to the attacker.
OSV
CVE-2018-8956: ntpd in ntp 4
osv·2020-05-06·CVSS 5.3
CVE-2018-8956 [MEDIUM] CVE-2018-8956: ntpd in ntp 4
ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via soofed mode 3 and mode 5 packets. The attacker must either be a part of the same broadcast network or control a slave in that broadcast network that can capture certain required packets on the attacker's behalf and send them to the attacker.
Red Hat
ntp: ntpd allows remote attackers to prevent a broadcast client from synchronizing its clock
vendor_redhat·2020-05-06·CVSS 5.3
CVE-2018-8956 [MEDIUM] CWE-20 ntp: ntpd allows remote attackers to prevent a broadcast client from synchronizing its clock
ntp: ntpd allows remote attackers to prevent a broadcast client from synchronizing its clock
ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via soofed mode 3 and mode 5 packets. The attacker must either be a part of the same broadcast network or control a slave in that broadcast network that can capture certain required packets on the attacker's behalf and send them to the attacker.
Statement: As per the researcher this issue only affects NTP versions 4.2.8p10 through 4.2.8p13, which are not shipped with any Red Hat products, therefore they are not affected by this flaw.
Package: ntp (Red Hat Enterprise Linux 5) - Not affected
Package: ntp (Red Hat Enterprise Linux 6) -
Debian
CVE-2018-8956: ntp - ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to ...
vendor_debian·2018·CVSS 5.3
CVE-2018-8956 [MEDIUM] CVE-2018-8956: ntp - ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to ...
ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via soofed mode 3 and mode 5 packets. The attacker must either be a part of the same broadcast network or control a slave in that broadcast network that can capture certain required packets on the attacker's behalf and send them to the attacker.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p14+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-8956 ntp: ntpd allows remote attackers to prevent a broadcast client from synchronizing its clock
bugzilla·2020-06-18·CVSS 5.3
CVE-2018-8956 [MEDIUM] CVE-2018-8956 ntp: ntpd allows remote attackers to prevent a broadcast client from synchronizing its clock
CVE-2018-8956 ntp: ntpd allows remote attackers to prevent a broadcast client from synchronizing its clock
ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via spoofed mode 3 and mode 5 packets. The attacker must either be a part of the same broadcast network or control a slave in that broadcast network that can capture certain required packets on the attacker's behalf and send them to the attacker.
References:
https://arxiv.org/abs/2005.01783
https://nikhiltripathi.in/NTP_attack.pdf
https://security.netapp.com/advisory/ntap-20200518-0006/
Discussion:
Created ntp tracking bugs for this issue:
Affects: fedora-all [bug 1848590]
---
Statement:
As per the researcher this
Bugzilla
CVE-2018-8956 ntp: ntpd allows remote attackers to prevent a broadcast client from synchronizing its clock [fedora-all]
bugzilla·2020-06-18·CVSS 5.3
CVE-2018-8956 [MEDIUM] CVE-2018-8956 ntp: ntpd allows remote attackers to prevent a broadcast client from synchronizing its clock [fedora-all]
CVE-2018-8956 ntp: ntpd allows remote attackers to prevent a broadcast client from synchronizing its clock [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
arXiv
Preventing Time Synchronization in NTP's Broadcast Mode
arxiv_fulltext·2020-05-14
Preventing Time Synchronization in NTP's Broadcast Mode
Preventing Time Synchronization in NTP's Broadcast Mode
Nikhil Tripathi1,
Neminath Hubballi2
Nikhil Tripathi is with Technical University of Darmstadt, Rheinstr. 75, 64295 Darmstadt, Germany. Neminath Hubballi is with Discipline of Computer Science and Engineering, Indian Institute of Technology Indore, India. (E-mails:[email protected], [email protected]). 1Corresponding Author
## Abstract
Network Time Protocol (NTP) is used by millions of hosts in Internet today to synchronize their clocks. Clock synchronization is necessary for many network applications to function correctly. Unsynchronized clock may lead to failure of various core Internet services including DNS and RPKI based interdomain routing and opens path for more sophisticated attacks. In this paper
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00044.htmlhttp://www.ntp.org/https://arxiv.org/abs/2005.01783https://nikhiltripathi.in/NTP_attack.pdfhttps://security.netapp.com/advisory/ntap-20200518-0006/https://tools.ietf.org/html/rfc5905http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00044.htmlhttp://www.ntp.org/https://arxiv.org/abs/2005.01783https://nikhiltripathi.in/NTP_attack.pdfhttps://security.netapp.com/advisory/ntap-20200518-0006/https://tools.ietf.org/html/rfc5905
2020-05-06
Published