Note:
This project will be discontinued after December 13, 2021. [more]
2017-01-30
NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote attackers to cause a denial of service (ntpd abort) by using the same IP address multiple times in an unconfig directive.
Products | Ntp |
Type | Improper Input Validation (CWE-20) |
First patch | - None (likely due to unavailable code) |
Links |
• http://support.ntp.org/bin/view/Main/NtpBug3011
• https://security.FreeBSD.org/advisories/FreeBSD-SA-16:16.ntp.asc • https://security.netapp.com/advisory/ntap-20171004-0002/ • https://security.gentoo.org/glsa/201607-15 • http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html |