CVE-2020-15025
published 2020-06-24CVE-2020-15025: ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets…
PriorityP425medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
3.36%
87.4th percentile
ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ntp | < ntp 1:4.2.8p15-1 (bullseye) | ntp 1:4.2.8p15-1 (bullseye) |
| debian | ntpsec | < ntp 1:4.2.8p15-1 (bullseye) | ntp 1:4.2.8p15-1 (bullseye) |
| ntp | ntp | — | — |
| ntp | ntp | >= 0 < 1:4.2.8p15-1 | 1:4.2.8p15-1 |
| ntp | ntp | >= 4.3.97 < 4.3.101 | 4.3.101 |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.9MEDIUM
vendor_debian4.4LOW
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p62f-hvr2-5w5f: ntpd in ntp 4
ghsa_unreviewed·2022-05-24
CVE-2020-15025 [MEDIUM] CWE-401 GHSA-p62f-hvr2-5w5f: ntpd in ntp 4
ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.
OSV
CVE-2020-15025: ntpd in ntp 4
osv·2020-06-24·CVSS 4.9
CVE-2020-15025 [MEDIUM] CVE-2020-15025: ntpd in ntp 4
ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.
Ubuntu
NTP vulnerability
vendor_ubuntu·2021-12-06
CVE-2020-15025 NTP vulnerability
Title: NTP vulnerability
Summary: A security issue was fixed in NTP.
It was discovered that ntpd incorrectly handled memory when CMAC keys
were used. A remote attacker could possibly use this issue to cause ntpd to
crash resulting in a denial of service.
Instructions: After a standard system update you need to restart the ntpd service
to make all the necessary changes.
Red Hat
ntp: Resource exhaustion via memory leak with CMAC keys
vendor_redhat·2020-06-23·CVSS 4.4
CVE-2020-15025 [MEDIUM] CWE-400 ntp: Resource exhaustion via memory leak with CMAC keys
ntp: Resource exhaustion via memory leak with CMAC keys
ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.
Statement: As per upstream, this issue only affects ntp-4.2.8p11p to ntp-4.2.8p14p, and 4.3.97 to 4.3.100. These packages versions do not ship with any Red Hat products, therefore they are not affected by this flaw.
Package: ntp (Red Hat Enterprise Linux 5) - Not affected
Package: ntp (Red Hat Enterprise Linux 6) - Not affected
Package: ntp (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2020-15025: ntp - ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attacke...
vendor_debian·2020·CVSS 4.4
CVE-2020-15025 [MEDIUM] CVE-2020-15025: ntp - ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attacke...
ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p15-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-15025 ntp: memory leak with CMAC keys can lead to DoS [fedora-all]
bugzilla·2020-06-29·CVSS 4.4
CVE-2020-15025 [MEDIUM] CVE-2020-15025 ntp: memory leak with CMAC keys can lead to DoS [fedora-all]
CVE-2020-15025 ntp: memory leak with CMAC keys can lead to DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions o
Bugzilla
CVE-2020-15025 ntp: Resource exhaustion via memory leak with CMAC keys
bugzilla·2020-06-24·CVSS 4.4
CVE-2020-15025 [MEDIUM] CVE-2020-15025 ntp: Resource exhaustion via memory leak with CMAC keys
CVE-2020-15025 ntp: Resource exhaustion via memory leak with CMAC keys
A flaw was found in ntp before version 4.2.8p15. Systems that use a CMAC algorithm in ntp.keys will not release a bit of memory on each packet that uses a CMAC keyid, eventually causing ntpd to run out of memory and fail.
References:
http://support.ntp.org/bin/view/Main/SecurityNotice#June_2020_ntp_4_2_8p15_NTP_Relea
http://support.ntp.org/bin/view/Main/NtpBug3661
Discussion:
Created ntp tracking bugs for this issue:
Affects: fedora-all [bug 1850531]
---
Created ntp tracking bugs for this issue:
Affects: fedora-all [bug 1850531]
---
Statement:
As per upstream, this issue only affects ntp-4.2.8p11p to ntp-4.2.8p14p, and 4.3.97 to 4.3.100. These packages versions do not ship with any Red Hat products, therefor
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00044.htmlhttps://bugs.gentoo.org/729458https://security.gentoo.org/glsa/202007-12https://security.netapp.com/advisory/ntap-20200702-0002/https://support.ntp.org/bin/view/Main/NtpBug3661https://support.ntp.org/bin/view/Main/SecurityNotice#June_2020_ntp_4_2_8p15_NTP_Releahttps://www.oracle.com/security-alerts/cpujan2021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00044.htmlhttps://bugs.gentoo.org/729458https://security.gentoo.org/glsa/202007-12https://security.netapp.com/advisory/ntap-20200702-0002/https://support.ntp.org/bin/view/Main/NtpBug3661https://support.ntp.org/bin/view/Main/SecurityNotice#June_2020_ntp_4_2_8p15_NTP_Releahttps://www.oracle.com/security-alerts/cpujan2021.html
2020-06-24
Published