CVE Database
/

CVE-2016-2517

Back to search

CVE-2016-2517

Published: Jan 30, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (prevent subsequent authentication) by leveraging knowledge of the controlkey or requestkey and sending a crafted packet to ntpd, which changes the value of trustedkey, controlkey, or requestkey. NOTE: this vulnerability exists because of a CVE-2016-2516 regression.

VendorProductVersions

n/a

n/a

affected
n/a

References

88189
vdb-entry
x_refsource_BID
VU#718152
third-party-advisory
x_refsource_CERT-VN
1035705
vdb-entry
x_refsource_SECTRACK
FreeBSD-SA-16:16
vendor-advisory
x_refsource_FREEBSD
GLSA-201607-15
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now