Back to search
CVE-2016-2517
Published: Jan 30, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (prevent subsequent authentication) by leveraging knowledge of the controlkey or requestkey and sending a crafted packet to ntpd, which changes the value of trustedkey, controlkey, or requestkey. NOTE: this vulnerability exists because of a CVE-2016-2516 regression.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://support.ntp.org/bin/view/Main/NtpBug3010
x_refsource_CONFIRM
88189
vdb-entry
x_refsource_BID
VU#718152
third-party-advisory
x_refsource_CERT-VN
1035705
vdb-entry
x_refsource_SECTRACK
https://security.netapp.com/advisory/ntap-20171004-0002/
x_refsource_CONFIRM
FreeBSD-SA-16:16
vendor-advisory
x_refsource_FREEBSD
GLSA-201607-15
vendor-advisory
x_refsource_GENTOO
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now