Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Debian Jessie DSA-3629-1 Critical: NTP Security Flaws and Fixes

debian
Calendar Grey July 25, 2016
Debian Logo
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ----------------------------------------------------
Several vulnerabilities were discovered in the Network Time Protocol daemon and utility programs: CVE-2015-7974

Summary

Several vulnerabilities were discovered in the Network Time Protocol
daemon and utility programs:

CVE-2015-7974

Matt Street discovered that insufficient key validation allows
impersonation attacks between authenticated peers.

CVE-2015-7977 / CVE-2015-7978

Stephen Gray discovered that a NULL pointer dereference and a
buffer overflow in the handling of "ntpdc reslist" commands may
result in denial of service.

CVE-2015-7979

Aanchal Malhotra discovered that if NTP is configured for broadcast
mode, an attacker can send malformed authentication packets which
break associations with the server for other broadcast clients.

CVE-2015-8138

Matthew van Gundy and Jonathan Gardner discovered that missing
validation of origin timestamps in ntpd clients may result in denial
of service.

CVE-2015-8158

Jonathan Gardner discovered that missing input sanitising in ntpq
may result in denial of service.

CVE-2016-1547

Stephen Gray and Matthew van Gundy discovered that inc...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: ntp
CVE ID: CVE-2015-7974 CVE-2015-7977 CVE-2015-7978 CVE-2015-7979

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here