|
|
Log in / Subscribe / Register

ntp: missing check for zero originate timestamp

Package(s):ntp CVE #(s):CVE-2015-8138
Created:January 25, 2016 Updated:November 11, 2016
Description: From the Red Hat advisory:

It was discovered that ntpd as a client did not correctly check the originate timestamp in received packets. A remote attacker could use this flaw to send a crafted packet to an ntpd client that would effectively disable synchronization with the server, or push arbitrary offset/delay measurements to modify the time on the client.

Alerts:
Oracle ELSA-2016-2583 ntp 2016-11-10
Ubuntu USN-3096-1 ntp 2016-10-05
SUSE SUSE-SU-2016:2094-1 yast2-ntp-client 2016-08-17
SUSE SUSE-SU-2016:1912-1 ntp 2016-07-29
Debian-LTS DLA-559-1 ntp 2016-07-25
Debian DSA-3629-1 ntp 2016-07-25
Gentoo 201607-15 ntp 2016-07-20
Fedora FEDORA-2016-8bb1932088 ntp 2016-01-30
Mageia MGASA-2016-0039 ntp 2016-01-29
Oracle ELSA-2016-0063 ntp 2016-01-25
Scientific Linux SLSA-2016:0063-1 ntp 2016-01-25
Oracle ELSA-2016-0063 ntp 2016-01-25
CentOS CESA-2016:0063 ntp 2016-01-25
CentOS CESA-2016:0063 ntp 2016-01-25
Red Hat RHSA-2016:0063-01 ntp 2016-01-25
openSUSE openSUSE-SU-2016:1423-1 ntp 2016-05-27
SUSE SUSE-SU-2016:1311-1 ntp 2016-05-17
Oracle ELSA-2016-0780 ntp 2016-05-13
openSUSE openSUSE-SU-2016:1292-1 ntp 2016-05-12
SUSE SUSE-SU-2016:1247-1 ntp 2016-05-06
Slackware SSA:2016-120-01 ntp 2016-04-29
SUSE SUSE-SU-2016:1177-1 ntp 2016-04-28
SUSE SUSE-SU-2016:1175-1 ntp 2016-04-28
Slackware SSA:2016-054-04 ntp 2016-02-23
Fedora FEDORA-2016-34bc10a2c8 ntp 2016-02-21

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds