Last update: April 22, 2024 18:49 UTC (7e7bd5857)
Resolved | 4.2.8p9 | 21 Nov 2016 |
---|---|---|
References | Bug 3082 | CVE-2016-7434 |
Affects | ntp-4.2.7p22, up to but not including ntp-4.2.8p9, and ntp-4.3.0 up to, but not including ntp-4.3.94. |
Resolved in 4.2.8p9. |
CVSS2 Score | LOW 3.8 | AV:L/AC:H/Au:S/C:N/I:N/A:C |
CVSS3 Score | LOW 3.8 | CVSS:3.0/AV:P/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H |
If ntpd
is configured to allow mrulist
query requests from a server that sends a crafted malicious packet, ntpd
will crash on receipt of that crafted malicious mrulist
query packet.
mrulist
query packets from trusted hosts.ntpd
instances, and auto-restart ntpd
(without -g
) if it stops running.This weakness was discovered by Magnus Stubman.