Vulnerability Description
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-1548.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ntp | Ntp | >= 4.2.0, < 4.2.8 |
| Oracle | Solaris | 10 |
| Suse | Manager Proxy | 2.1 |
| Suse | Openstack Cloud | 5 |
| Novell | Suse Manager | 2.1 |
| Opensuse | Leap | 42.1 |
| Opensuse | Opensuse | 13.2 |
| Suse | Linux Enterprise Desktop | 12 |
| Suse | Linux Enterprise Server | 11 |
| Siemens | Simatic Net Cp 443-1 Opc Ua Firmware | All versions |
| Siemens | Simatic Net Cp 443-1 Opc Ua | - |
References
- http://bugs.ntp.org/3042Issue TrackingVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00018.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00020.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00023.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00024.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00028.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00040.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00026.html
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00042.html
- http://packetstormsecurity.com/files/137321/Slackware-Security-Advisory-ntp-Upda
- http://support.ntp.org/bin/view/Main/NtpBug3042Vendor Advisory
- http://support.ntp.org/bin/view/Main/SecurityNoticeRelease NotesVendor Advisory
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20
- http://www.kb.cert.org/vuls/id/321640Third Party AdvisoryUS Government Resource
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlThird Party Advisory
FAQ
What is CVE-2016-4956?
CVE-2016-4956 is a vulnerability with a CVSS score of 5.3 (MEDIUM). ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists becau...
How severe is CVE-2016-4956?
CVE-2016-4956 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-4956?
Check the references section above for vendor advisories and patch information. Affected products include: Ntp Ntp, Oracle Solaris, Suse Manager Proxy, Suse Openstack Cloud, Novell Suse Manager.