NTP BUG 2902: Configuration directives to change pidfile and driftfile should only be allowed locally

Last update: June 28, 2022 20:06 UTC (57417e17c)


Summary

Resolved 4.2.8p4 21 Oct 2015
References Bug 2902 CVE-2015-7703
Affects All ntp-4 releases up to, but not including 4.2.8p4,
and 4.3.0 up to, but not including 4.3.77.
Resolved in 4.2.8p4
CVSS2 Score 6.2 worst case AV:N/AC:H/Au:M/C:N/I:C/A:C

Description

If ntpd is configured to allow for remote configuration, and if the (possibly spoofed) source IP address is allowed to send remote configuration requests, and if the attacker knows the remote configuration password, it’s possible for an attacker to use the pidfile or driftfile directives to potentially overwrite other files.


Mitigation


Credit

This weakness was discovered by Miroslav Lichvar of Red Hat.


Timeline