vulnerability
Amazon Linux AMI 2: CVE-2016-7426: Security patch for ntp (ALAS-2018-1009)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
4 | (AV:N/AC:M/Au:N/C:N/I:N/A:P) | Jan 13, 2017 | Apr 27, 2020 | May 5, 2025 |
Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
Jan 13, 2017
Added
Apr 27, 2020
Modified
May 5, 2025
Description
NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.
Solution(s)
amazon-linux-ami-2-upgrade-ntpamazon-linux-ami-2-upgrade-ntp-debuginfoamazon-linux-ami-2-upgrade-ntp-docamazon-linux-ami-2-upgrade-ntp-perlamazon-linux-ami-2-upgrade-ntpdateamazon-linux-ami-2-upgrade-sntp

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.