NTP BUG 3082: read_mru_list() does inadequate incoming packet checks

Last update: February 15, 2022 20:59 UTC (43fbd379b)


Summary

Resolved 4.2.8p9 21 Nov 2016
References Bug 3082 CVE-2016-7434
Affects ntp-4.2.7p22, up to but not including ntp-4.2.8p9,
and ntp-4.3.0 up to, but not including ntp-4.3.94.
Resolved in 4.2.8p9.
CVSS2 Score LOW 3.8 AV:L/AC:H/Au:S/C:N/I:N/A:C
CVSS3 Score LOW 3.8 CVSS:3.0/AV:P/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H

Description

If ntpd is configured to allow mrulist query requests from a server that sends a crafted malicious packet, ntpd will crash on receipt of that crafted malicious mrulist query packet.


Mitigation


Credit

This weakness was discovered by Magnus Stubman.


Timeline