ntp: missing check for zero originate timestamp
| Package(s): | ntp |
CVE #(s): | CVE-2015-8138
|
| Created: | January 25, 2016 |
Updated: | November 11, 2016 |
| Description: |
From the Red Hat advisory:
It was discovered that ntpd as a client did not correctly check the
originate timestamp in received packets. A remote attacker could use this
flaw to send a crafted packet to an ntpd client that would effectively
disable synchronization with the server, or push arbitrary offset/delay
measurements to modify the time on the client. |
| Alerts: |
|