The receive function in ntp_proto.c in ntpd in NTP before 4.2.8 continues to execute after detecting a certain authentication error, which might allow remote attackers to trigger an unintended association change via crafted packets.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade ntp-docUpgrade ntpdateUpgrade ntp-perlUpgrade ntpUpgrade sntp | Dec 1, 2016 | Dec 19, 2014 |
| Debian | — | Upgrade ntp | Jul 30, 2024 | Dec 20, 2014 |
| Freebsd | — | Upgrade ntpUpgrade ntp-devel | Dec 10, 2025 | Dec 20, 2014 |
| Gentoo Linux | — | Upgrade net-misc/ntp. | Oct 30, 2017 | Dec 19, 2014 |
| Hpux | — | Update NTP.NTP-AUX to the latest versionApply patch PHNE_44236 from HPUpdate NTP.NTP-RUN to the latest versionUpdate NTP.INETSVCS2-BOOT to the latest versionApply patch PHNE_44235 from HP | Aug 11, 2017 | Dec 19, 2014 |
| Ntp | — | Upgrade to the latest version of NTP | Feb 23, 2023 | Dec 20, 2014 |
| Oracle Solaris | — | Upgrade service/network/ntp to version 4.2.8-0.175.2.6.0.4.0 on Solaris 11.2 | May 29, 2017 | Dec 19, 2014 |
| Oracle_linux | — | Upgrade ntp-docUpgrade ntpUpgrade ntp-perlUpgrade ntpdateUpgrade sntp | Oct 16, 2024 | Dec 20, 2014 |
| Suse | — | Upgrade ntp-docUpgrade ntp | Dec 18, 2015 | Dec 19, 2014 |
| Ubuntu | — | Upgrade ntp | Nov 8, 2024 | Dec 20, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub