Vulnerability Description
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ntp | Ntp | 4.2.8 |
| Oracle | Solaris | 10 |
| Suse | Manager Proxy | 2.1 |
| Suse | Openstack Cloud | 5 |
| Novell | Suse Manager | 2.1 |
| Opensuse | Leap | 42.1 |
| Opensuse | Opensuse | 13.2 |
| Suse | Linux Enterprise Desktop | 12 |
| Suse | Linux Enterprise Server | 11 |
Related Weaknesses (CWE)
References
- http://bugs.ntp.org/3046Issue TrackingVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00018.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00023.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00024.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00028.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00040.htmlMailing ListThird Party Advisory
- http://support.ntp.org/bin/view/Main/NtpBug3046PatchVendor Advisory
- http://support.ntp.org/bin/view/Main/SecurityNoticeRelease NotesVendor Advisory
- http://www.kb.cert.org/vuls/id/321640Third Party AdvisoryUS Government Resource
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlThird Party Advisory
- http://www.securitytracker.com/id/1036037Third Party AdvisoryVDB Entry
- https://security.FreeBSD.org/advisories/FreeBSD-SA-16:24.ntp.ascThird Party Advisory
- https://security.gentoo.org/glsa/201607-15Third Party Advisory
- http://bugs.ntp.org/3046Issue TrackingVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00018.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2016-4957?
CVE-2016-4957 is a vulnerability with a CVSS score of 7.5 (HIGH). ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.
How severe is CVE-2016-4957?
CVE-2016-4957 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-4957?
Check the references section above for vendor advisories and patch information. Affected products include: Ntp Ntp, Oracle Solaris, Suse Manager Proxy, Suse Openstack Cloud, Novell Suse Manager.