Red Hat Bugzilla – Bug 1166596
ntpd should warn when monitoring facility can't be disabled due to restrict configuration
Last modified: 2015-07-22 03:00:08 EDT
Description of problem: When ntpd is configured with a restrict directive using the limited option, disabling the monitoring facility with "disable monitor" will have no effect. ntpd should print a warning to syslog when that happens to avoid unknowingly allowing the monlist amplification attack (CVE-2013-5211). Version-Release number of selected component (if applicable): 4.2.6p5-1.el6 How reproducible: always Steps to Reproduce: 1. add "limited" to the default restrict lines in /etc/ntp.conf 2. add "disable monitor" to /etc/ntp.conf 3. start ntpd Actual results: no warning in syslog, that monitor couldn't be disabled Expected results: warning in syslog Additional info:
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHSA-2015-1459.html