NTP BUG 3119: Mode 6 unauthenticated trap information disclosure and DDoS vector

Last update: June 27, 2022 20:45 UTC (51d68a4aa)


Summary

Resolved 4.2.8p9 21 Nov 2016
References Bug 3119 CVE-2016-9311
Affects ntp-4.0.90 (21 July 1999), possibly earlier, up to but not
including ntp-4.2.8p9, and ntp-4.3.0 up to, but not including ntp-4.3.94.
Resolved in 4.2.8p9.
CVSS2 Score MED 4.9 AV:N/AC:H/Au:N/C:N/I:N/A:C
CVSS3 Score MED 4.4 CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H

Description

ntpd does not enable trap service by default. If trap service has been explicitly enabled, an attacker can send a specially crafted packet to cause a null pointer dereference that will crash ntpd, resulting in a denial of service.


Mitigation


Credit

This weakness was discovered by Matthew Van Gundy of Cisco.


Timeline