ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.
The product does not properly verify that the source of data or communication is valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ntp | Ntp | * | 4.2.7 (including) |
Ntp | Ntp | 4.3.98 (including) | 4.3.100 (excluding) |
Ntp | Ntp | 4.2.8 (including) | 4.2.8 (including) |
Ntp | Ntp | 4.2.8-p1 (including) | 4.2.8-p1 (including) |
Ntp | Ntp | 4.2.8-p1-beta1 (including) | 4.2.8-p1-beta1 (including) |
Ntp | Ntp | 4.2.8-p1-beta2 (including) | 4.2.8-p1-beta2 (including) |
Ntp | Ntp | 4.2.8-p1-beta3 (including) | 4.2.8-p1-beta3 (including) |
Ntp | Ntp | 4.2.8-p1-beta4 (including) | 4.2.8-p1-beta4 (including) |
Ntp | Ntp | 4.2.8-p1-beta5 (including) | 4.2.8-p1-beta5 (including) |
Ntp | Ntp | 4.2.8-p1-rc1 (including) | 4.2.8-p1-rc1 (including) |
Ntp | Ntp | 4.2.8-p1-rc2 (including) | 4.2.8-p1-rc2 (including) |
Ntp | Ntp | 4.2.8-p10 (including) | 4.2.8-p10 (including) |
Ntp | Ntp | 4.2.8-p11 (including) | 4.2.8-p11 (including) |
Ntp | Ntp | 4.2.8-p12 (including) | 4.2.8-p12 (including) |
Ntp | Ntp | 4.2.8-p13 (including) | 4.2.8-p13 (including) |
Ntp | Ntp | 4.2.8-p2 (including) | 4.2.8-p2 (including) |
Ntp | Ntp | 4.2.8-p2-rc1 (including) | 4.2.8-p2-rc1 (including) |
Ntp | Ntp | 4.2.8-p2-rc2 (including) | 4.2.8-p2-rc2 (including) |
Ntp | Ntp | 4.2.8-p2-rc3 (including) | 4.2.8-p2-rc3 (including) |
Ntp | Ntp | 4.2.8-p3 (including) | 4.2.8-p3 (including) |
Ntp | Ntp | 4.2.8-p3-rc1 (including) | 4.2.8-p3-rc1 (including) |
Ntp | Ntp | 4.2.8-p3-rc2 (including) | 4.2.8-p3-rc2 (including) |
Ntp | Ntp | 4.2.8-p3-rc3 (including) | 4.2.8-p3-rc3 (including) |
Ntp | Ntp | 4.2.8-p4 (including) | 4.2.8-p4 (including) |
Ntp | Ntp | 4.2.8-p5 (including) | 4.2.8-p5 (including) |
Ntp | Ntp | 4.2.8-p6 (including) | 4.2.8-p6 (including) |
Ntp | Ntp | 4.2.8-p7 (including) | 4.2.8-p7 (including) |
Ntp | Ntp | 4.2.8-p8 (including) | 4.2.8-p8 (including) |
Ntp | Ntp | 4.2.8-p9 (including) | 4.2.8-p9 (including) |
Red Hat Enterprise Linux 7 | RedHat | ntp-0:4.2.6p5-29.el7_8.2 | * |
Ntp | Ubuntu | bionic | * |
Ntp | Ubuntu | eoan | * |
Ntp | Ubuntu | groovy | * |
Ntp | Ubuntu | hirsute | * |
Ntp | Ubuntu | impish | * |
Ntp | Ubuntu | precise/esm | * |
Ntp | Ubuntu | trusty | * |
Ntp | Ubuntu | trusty/esm | * |
Ntp | Ubuntu | upstream | * |
Ntp | Ubuntu | xenial | * |
Ntpsec | Ubuntu | bionic | * |
Ntpsec | Ubuntu | eoan | * |
Ntpsec | Ubuntu | groovy | * |
Ntpsec | Ubuntu | hirsute | * |
Ntpsec | Ubuntu | impish | * |
Ntpsec | Ubuntu | kinetic | * |
Ntpsec | Ubuntu | lunar | * |
Ntpsec | Ubuntu | mantic | * |
Ntpsec | Ubuntu | trusty | * |