vulnerability

Amazon Linux AMI: CVE-2016-7426: Security patch for ntp (ALAS-2017-781)

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
Jan 4, 2017
Added
Jan 5, 2017
Modified
Oct 14, 2022

Description

NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.

Solution

amazon-linux-upgrade-ntp
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.