ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp. This issue is a result of an incomplete fix for CVE-2015-7704.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade ntp | May 11, 2018 | Mar 6, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Mar 6, 2018 |
| Debian | — | Upgrade ntp | Jul 30, 2024 | Mar 6, 2018 |
| F5 Big Ip | — | — | Mar 27, 2018 | Mar 6, 2018 |
| Freebsd | — | Upgrade ntpUpgrade ntp-develUpgrade FreeBSD | May 6, 2018 | Feb 28, 2018 |
| Gentoo Linux | — | Upgrade net-misc/ntp. | May 29, 2018 | Mar 6, 2018 |
| Hpux | — | Update NTP to the latest version | Dec 9, 2019 | Mar 6, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade ntpdateUpgrade ntp | Nov 3, 2020 | Mar 6, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade sntpUpgrade ntpdateUpgrade ntp | Nov 19, 2019 | Mar 6, 2018 |
| Ibm Aix | — | Apply the fix or workaround for ntp_advisory10 | Aug 16, 2018 | Mar 6, 2018 |
| Ntp | — | Upgrade to the latest version of NTP | Feb 23, 2023 | Mar 6, 2018 |
| Oracle Solaris | — | Upgrade service/network/ntp to version 4.2.8.11-0.175.3.31.0.4.0 on Solaris 11.3 | Apr 18, 2018 | Mar 6, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 6, 2018 |
| Suse | — | Upgrade ntp-docUpgrade ntp | Mar 28, 2018 | Mar 6, 2018 |
| Ubuntu | — | Upgrade ntp | Jul 13, 2018 | Mar 6, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 6, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub