ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before...
Vulnerability Description
ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp. This issue is a result of an incomplete fix for CVE-2015-7704.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-7184
Credits & Attribution
No credits recorded in the NVD database.
References
- http://packetstormsecurity.com/files/146631/Slackware-Security-Advisory-ntp-Updates.html
- http://www.securityfocus.com/bid/103192
- https://security.gentoo.org/glsa/201805-12
- https://security.FreeBSD.org/advisories/FreeBSD-SA-18:02.ntp.asc
- https://security.netapp.com/advisory/ntap-20180626-0001/
- http://www.securityfocus.com/archive/1/541824/100/0/threaded
- http://support.ntp.org/bin/view/Main/NtpBug3453
- https://usn.ubuntu.com/3707-1/
- https://www.synology.com/support/security/Synology_SA_18_13
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_us
More from ntp
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.