CVE-2019-8936
published 2019-05-15CVE-2019-8936: NTP through 4.2.8p12 has a NULL Pointer Dereference.
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
5.73%
92.2th percentile
NTP through 4.2.8p12 has a NULL Pointer Dereference.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ntp | < ntp 1:4.2.8p12+dfsg-4 (bullseye) | ntp 1:4.2.8p12+dfsg-4 (bullseye) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| hpe | hpux-ntp | < c.4.2.8.4.0 | c.4.2.8.4.0 |
| netapp | clustered_data_ontap | < 9.2 | 9.2 |
| ntp | ntp | < 4.2.8 | 4.2.8 |
| ntp | ntp | — | — |
| ntp | ntp | >= 0 < 1:4.2.8p12+dfsg-4 | 1:4.2.8p12+dfsg-4 |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-54w8-prj8-6v5f: NTP through 4
ghsa_unreviewed·2022-05-24
CVE-2019-8936 [HIGH] CWE-476 GHSA-54w8-prj8-6v5f: NTP through 4
NTP through 4.2.8p12 has a NULL Pointer Dereference.
OSV
CVE-2019-8936: NTP through 4
osv·2019-05-15·CVSS 7.5
CVE-2019-8936 [HIGH] CVE-2019-8936: NTP through 4
NTP through 4.2.8p12 has a NULL Pointer Dereference.
Ubuntu
NTP vulnerability
vendor_ubuntu·2021-04-20·CVSS 7.5
CVE-2019-8936 [HIGH] NTP vulnerability
Title: NTP vulnerability
Summary: NTP could be made to crash.
USN-4563-1 fixed a vulnerability in NTP. This update provides the
corresponding update for Ubuntu 20.04 LTS and Ubuntu 20.10.
Original advisory details:
It was discovered that the fix for CVE-2018-7182 introduced a NULL pointer
dereference into NTP. An attacker could use this vulnerability to cause a
denial of service (crash).
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
NTP vulnerability
vendor_ubuntu·2020-10-01·CVSS 7.5
CVE-2019-8936 [HIGH] NTP vulnerability
Title: NTP vulnerability
Summary: NTP could be made to crash.
It was discovered that the fix for CVE-2018-7182 introduced a NULL pointer
dereference into NTP. An attacker could use this vulnerability to cause a
denial of service (crash).
Instructions: In general, a standard system update will make all the necessary changes.
BSD
FreeBSD-SA-19:04.ntp: Authenticated denial of service in ntpd
bsd_advisories·2019-05-14·CVSS 7.5
CVE-2019-8936 [HIGH] FreeBSD-SA-19:04.ntp: Authenticated denial of service in ntpd
FreeBSD-SA-19:04.ntp Security Advisory
The FreeBSD Project
Topic: Authenticated denial of service in ntpd
Category: contrib
Module: ntp
Announced: 2019-05-14
Credits: Magnus Stubman
Affects: All supported versions of FreeBSD
Corrected: 2019-03-07 13:45:36 UTC (stable/12, 12.0-STABLE)
2019-05-14 23:02:56 UTC (releng/12.0, 12.0-RELEASE-p4)
2019-03-07 13:45:36 UTC (stable/11, 11.3-PRERELEASE)
2019-05-14 23:06:26 UTC (releng/11.2, 11.2-RELEASE-p10)
CVE Name: CVE-2019-8936
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
The ntpd(8) daemon is an implementation of the Network Time Protocol
(NTP) used to synchronize the time of a computer system to a reference
Red Hat
ntp: Crafted null dereference attack in authenticated mode 6 packet
vendor_redhat·2019-03-07·CVSS 7.5
CVE-2019-8936 [HIGH] CWE-119 ntp: Crafted null dereference attack in authenticated mode 6 packet
ntp: Crafted null dereference attack in authenticated mode 6 packet
NTP through 4.2.8p12 has a NULL Pointer Dereference.
Statement: This issue did not affect the versions of ntp as shipped with Red Hat Enterprise Linux 5, 6, and 7.
Package: ntp (Red Hat Enterprise Linux 5) - Not affected
Package: ntp (Red Hat Enterprise Linux 6) - Not affected
Package: ntp (Red Hat Enterprise Linux 7) - Not affected
Package: redhat-virtualization-host (Red Hat Virtualization 4) - Not affected
Debian
CVE-2019-8936: ntp - NTP through 4.2.8p12 has a NULL Pointer Dereference.
vendor_debian·2019·CVSS 7.5
CVE-2019-8936 [HIGH] CVE-2019-8936: ntp - NTP through 4.2.8p12 has a NULL Pointer Dereference.
NTP through 4.2.8p12 has a NULL Pointer Dereference.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p12+dfsg-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-8936 ntp: Crafted null dereference attack in authenticated mode 6 packet
bugzilla·2019-03-07·CVSS 7.5
CVE-2019-8936 [HIGH] CVE-2019-8936 ntp: Crafted null dereference attack in authenticated mode 6 packet
CVE-2019-8936 ntp: Crafted null dereference attack in authenticated mode 6 packet
A flaw was found in ntp before version 4.2.8p13. An authenticated attacker can cause ntpd to sigsegv by triggering a NULL pointer exception.
Upstream issue:
http://bugs.ntp.org/show_bug.cgi?id=3565
Upstream patch:
http://bk.ntp.org/ntp-stable/ntpd/ntp_control.c?PAGE=diffs&REV=5c8106e7wWtXdh0lzg1ytlWribBTcQ
References:
https://gitlab.com/NTPsec/ntpsec/issues/509
Discussion:
Created ntp tracking bugs for this issue:
Affects: fedora-all [bug 1686606]
---
Although the RHEL7 version is missing the NULL checks added in this patch, it does not crash with the POC provided. It seems like this was introduced in later versions due to changes in the ctl_getitem() function in ntpd/ntp_control.c, which are not
Bugzilla
CVE-2019-8936 ntp: Crafted null dereference attack in authenticated mode 6 packet [fedora-all]
bugzilla·2019-03-07·CVSS 7.5
CVE-2019-8936 [HIGH] CVE-2019-8936 ntp: Crafted null dereference attack in authenticated mode 6 packet [fedora-all]
CVE-2019-8936 ntp: Crafted null dereference attack in authenticated mode 6 packet [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple s
http://bugs.ntp.org/show_bug.cgi?id=3565http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00036.htmlhttp://packetstormsecurity.com/files/152915/FreeBSD-Security-Advisory-FreeBSD-SA-19-04.ntp.htmlhttp://support.ntp.org/bin/view/Main/SecurityNoticehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2NVS2CSG2TQ663CXOZZUJN4STQPMENNP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JBGXY7OKWOLT6X6JAPVZRFEP4FLCGGST/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQDNHNYOJK2SRSGO23GQ2RXTOUY2HLNN/https://seclists.org/bugtraq/2019/May/39https://security.FreeBSD.org/advisories/FreeBSD-SA-19:04.ntp.aschttps://security.gentoo.org/glsa/201903-15https://security.netapp.com/advisory/ntap-20190503-0001/https://support.f5.com/csp/article/K61363039https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_ushttps://usn.ubuntu.com/4563-1/http://bugs.ntp.org/show_bug.cgi?id=3565http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00036.htmlhttp://packetstormsecurity.com/files/152915/FreeBSD-Security-Advisory-FreeBSD-SA-19-04.ntp.htmlhttp://support.ntp.org/bin/view/Main/SecurityNoticehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2NVS2CSG2TQ663CXOZZUJN4STQPMENNP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JBGXY7OKWOLT6X6JAPVZRFEP4FLCGGST/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQDNHNYOJK2SRSGO23GQ2RXTOUY2HLNN/https://seclists.org/bugtraq/2019/May/39https://security.FreeBSD.org/advisories/FreeBSD-SA-19:04.ntp.aschttps://security.gentoo.org/glsa/201903-15https://security.netapp.com/advisory/ntap-20190503-0001/https://support.f5.com/csp/article/K61363039https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_ushttps://usn.ubuntu.com/4563-1/
2019-05-15
Published