ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.
CVSS Details
- CVSS 3.1 Base Score: 4.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ntp | Jul 30, 2024 | Jun 24, 2020 |
| Gentoo Linux | — | Upgrade net-misc/ntp. | Jul 28, 2020 | Jun 24, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade ntpUpgrade sntpUpgrade ntpdate | Nov 3, 2020 | Jun 24, 2020 |
| Ibm Aix | — | Apply the fix or workaround for ntp_advisory13 | Oct 27, 2020 | Jun 24, 2020 |
| Ntp | — | Upgrade NTP to version 4.3.101 | Feb 23, 2023 | Jun 24, 2020 |
| Oracle Solaris | — | Upgrade service/network/ntp to version 4.2.8.15-11.4.27.0.1.82.0 on Solaris 11.4 | Jan 19, 2021 | Jun 24, 2020 |
| Suse | — | Upgrade ntp-docUpgrade ntp | Jul 1, 2020 | Jun 24, 2020 |
| Ubuntu | — | Upgrade ntp (Ubuntu Pro) | Mar 22, 2023 | Jun 24, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 24, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub