This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Network Time Protocol update

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

Network Time Protocol update
- https://www.us-cert.gov/ncas/current-activity/2016/11/21/Vulnerabilities-Identified-Network-Time-Protocol-Daemon-ntpd
Nov 21, 2016 - "The Network Time Foundation's NTP Project has released version ntp-4.2.8p9 to address multiple vulnerabilities in ntpd. Exploitation of some of these vulnerabilities may allow a remote attacker to cause a denial-of-service condition.
US-CERT encourages users and administrators to review Vulnerability Note VU#633847* and the NTP Security Notice Page** for vulnerability and mitigation details."
* http://www.kb.cert.org/vuls/id/633847

** http://nwtime.org/ntp428p9_release/
___

- http://www.securitytracker.com/id/1037354
CVE Reference: CVE-2016-7426, CVE-2016-7427, CVE-2016-7428, CVE-2016-7429, CVE-2016-7431, CVE-2016-7433, CVE-2016-7434, CVE-2016-9310, CVE-2016-9311, CVE-2016-9312
Nov 29 2016
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): prior to 4.2.8p9 …
Impact: A remote user can cause the target service to crash.
A remote user can obtain potentially sensitive information from the target system.
A remote user can conduct denial of service amplification attacks against other targets.
Solution: The vendor has issued a fix (4.2.8p9)…
Vendor URL: http://support.ntp.org/bin/view/Main/SecurityNotice#November_2016_ntp_4_2_8p9_NTP_Se
 

:ph34r: :ph34r:

FYI…

NTP 4.2.8p10 released
- https://www.us-cert.gov/ncas/current-activity/2017/03/22/Vulnerabilities-Identified-Network-Time-Protocol-Daemon-ntpd
March 22, 2017 - "The Network Time Foundation's NTP Project has has released version ntp-4.2.8p10* to address multiple vulnerabilities in ntpd. Exploitation of some of these vulnerabilities may allow a remote attacker to cause a denial-of-service condition…"
* http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_Vulnerabilities
"… ntp-4.2.8p10 was released on 21 March 2017…"
___

- http://www.securitytracker.com/id/1038123
CVE Reference: CVE-2016-9042, CVE-2017-6451, CVE-2017-6452, CVE-2017-6455, CVE-2017-6458, CVE-2017-6459, CVE-2017-6460, CVE-2017-6462, CVE-2017-6463, CVE-2017-6464
Mar 24 2017
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 4.2.8p9 and prior…
Impact: A remote or local user can cause the target service to crash.
Solution: The vendor has issued a fix (4.2.8p10)…
 

:ph34r: