Resource management error in ntp - CVE-2020-13817

 

Resource management error in ntp - CVE-2020-13817

Published: March 19, 2020 / Updated: October 29, 2023


Vulnerability identifier: #VU26241
CSH Severity: Low
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-13817
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to ntpd uses highly predictable timestamps that can allow spoofing attack over IPv4 or a denial of service attack. A remote non-authenticated attacker can modify clock on the client NTP server to terminate it.


Affected software

ntp
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
FreeBSD
Opensuse
Junos OS Evolved
Fujitsu M10-4S
Fujitsu M10-1
Fujitsu M10-4
Data Computing Appliance (DCA)
Fujitsu M12-1
Fujitsu M12-2
Fujitsu M12-2S
Flex System Chassis Management Module (CMM)
ntp (Red Hat package)

How to mitigate CVE-2020-13817

Install updates from vendor's website.

ntp - update to 4.2.8p14
Junos OS Evolved - addressed in versions 21.2R3-S5-EVO, 21.3R3-S4-EVO, 21.4R3-S4-EVO, 22.1R3-S3-EVO, 22.2R3-EVO, 22.3R2-EVO, 22.4R2-EVO, 23.1R1-EVO
Flex System Chassis Management Module (CMM) - update to 2pet22a-2.5.20a
ntp (Red Hat package) - update to 4.2.6p5-29.el7_8.2
Data Computing Appliance (DCA) - update to 4.3.0.0

External References

Related Security Bulletins