Security restrictions bypass in Network Time Protocol - CVE-2016-1549

 

Security restrictions bypass in Network Time Protocol - CVE-2016-1549

Published: March 1, 2018


Vulnerability identifier: #VU10806
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-1549
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The weakness exists due to insufficient security restrictions. A remote attacker can create multiple crafted ephemeral associations to bypass security restrictions and modify the clock.

Affected software

Network Time Protocol
Arch Linux
Amazon Linux AMI
IBM AIX
Slackware Linux
Fedora
ntp

How to mitigate CVE-2016-1549

Install update from vendor's website.

ntp - addressed in versions 4.2.8p11-1.fc26, 4.2.8p11-1.fc27

External References

Related Security Bulletins