LWN.net Logo

ntp: denial of service

Package(s):ntp CVE #(s):CVE-2009-3563
Created:December 9, 2009 Updated:May 7, 2010
Description:

From the Red Hat advisory:

Robin Park and Dmitri Vinokurov discovered a flaw in the way ntpd handled certain malformed NTP packets. ntpd logged information about all such packets and replied with an NTP packet that was treated as malformed when received by another ntpd. A remote attacker could use this flaw to create an NTP packet reply loop between two ntpd servers via a malformed packet with a spoofed source IP address and port, causing ntpd on those servers to use excessive amounts of CPU time and fill disk space with log messages. (CVE-2009-3563)

Alerts:
rPath rPSA-2010-0034-1 2010-05-07
Debian DSA-1992-1 2010-02-04
SuSE SUSE-SR:2009:020 2010-01-12
Gentoo 201001-01 2010-01-04
CentOS CESA-2009:1648 2009-12-19
Fedora FEDORA-2009-13046 2009-12-11
Fedora FEDORA-2009-13090 2009-12-11
Fedora FEDORA-2009-13121 2009-12-11
Slackware SSA:2009-343-01 2009-12-10
Ubuntu USN-867-1 2009-12-08
Mandriva MDVSA-2009:328 2009-12-08
Debian DSA-1908-1 2009-12-08
CentOS CESA-2009:1648 2009-12-08
CentOS CESA-2009:1651 2009-12-08
Red Hat RHSA-2009:1648-01 2009-12-08
Red Hat RHSA-2009:1651-01 2009-12-08

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds