Back to Database
Status published
Medium
CVE-2016-2519
ntpd in NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows...
Vulnerability Description
ntpd in NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (ntpd abort) by a large request data value, which triggers the ctl_getitem function to return a NULL value.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-2519
Credits & Attribution
No credits recorded in the NVD database.
References
- http://support.ntp.org/bin/view/Main/NtpBug3008
- https://www.kb.cert.org/vuls/id/718152
- http://www.securitytracker.com/id/1035705
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- https://security.netapp.com/advisory/ntap-20171004-0002/
- https://security.FreeBSD.org/advisories/FreeBSD-SA-16:16.ntp.asc
- http://www.securityfocus.com/bid/88204
- https://security.gentoo.org/glsa/201607-15
More from ntp
View All →CVE-2020-15025
ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101...
Medium
4.4
CVE-2020-13817
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows...
Medium
5.9
CVE-2020-11868
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows...
Medium
5.9
CVE-2019-11331
Network Time Protocol (NTP), as specified in RFC 5905, uses...
High
8.1
CVE-2018-8956
ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote...
Medium
5.3
Affected Vendor
Affected Software
ntp
Vulnerable Versions:
0, 4.3.0, 4.3.1, 4.3.2, 4.3.3, 4.3.4, 4.3.5, 4.3.6, 4.3.7, 4.3.8, 4.3.9, 4.3.10, 4.3.11, 4.3.12, 4.3.13, 4.3.14, 4.3.15, 4.3.16, 4.3.17, 4.3.18, 4.3.19, 4.3.20, 4.3.21, 4.3.22, 4.3.23, 4.3.24, 4.3.25, 4.3.26, 4.3.27, 4.3.28, 4.3.29, 4.3.30, 4.3.31, 4.3.32, 4.3.33, 4.3.34, 4.3.35, 4.3.36, 4.3.37, 4.3.38, 4.3.39, 4.3.40, 4.3.41, 4.3.42, 4.3.43, 4.3.44, 4.3.45, 4.3.46, 4.3.47, 4.3.48, 4.3.49, 4.3.50, 4.3.51, 4.3.52, 4.3.53, 4.3.54, 4.3.55, 4.3.56, 4.3.57, 4.3.58, 4.3.59, 4.3.60, 4.3.61, 4.3.62, 4.3.63, 4.3.64, 4.3.65, 4.3.66, 4.3.67, 4.3.68, 4.3.69, 4.3.70, 4.3.71, 4.3.72, 4.3.73, 4.3.74, 4.3.75, 4.3.76, 4.3.77, 4.3.78, 4.3.79, 4.3.80, 4.3.81, 4.3.82, 4.3.83, 4.3.84, 4.3.85, 4.3.86, 4.3.87, 4.3.88, 4.3.89, 4.3.90, 4.3.91
Timeline
Official Publish:
January 30th, 2017
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.