NTP BUG 2916: memory corruption in password store

Last update: March 2, 2022 17:28 UTC (616623bea)


Summary

Resolved 4.2.8p4 21 Oct 2015
References Bug 2916 CVE-2015-7849
Affects All ntp-4 releases up to, but not including 4.2.8p4,
and 4.3.0 up to, but not including 4.3.77.
Resolved in 4.2.8p4.
CVSS2 Score 6.8, worst case AV:N/AC:H/Au:M/C:N/I:C/A:C

Description

If ntpd is configured to allow remote configuration, and if the (possibly spoofed) source IP address is allowed to send remote configuration requests, and if the attacker knows the remote configuration password or if ntpd was configured to disable authentication, then an attacker can send a set of packets to ntpd that may cause a crash or theoretically perform a code injection attack.


Mitigation


Credit

This weakness was discovered by Yves Younan of Cisco Talos.


Timeline