NTP BUG 2942: Off-path Denial of Service (DoS) attack on authenticated broadcast mode

Last update: February 15, 2022 20:59 UTC (43fbd379b)


Summary

Resolved 4.2.8p6 19 Jan 2016
References Bug 2942 CVE-2015-7979
Affects All ntp-4 releases up to, but not including 4.2.8p6,
and 4.3.0 up to, but not including 4.3.90.
Resolved in 4.2.8p6.
CVSS2 Score MED 5.8 AV:N/AC:M/Au:N/C:N/I:P/A:P

Description

An off-path attacker can send broadcast packets with bad authentication (wrong key, mismatched key, incorrect MAC, etc) to broadcast clients. It is observed that the broadcast client tears down the association with the broadcast server upon receiving just one bad packet.


Mitigation


Credit

This weakness was discovered by Aanchal Malhotra of Boston University.


Timeline