Bug 1848589 (CVE-2018-8956) - CVE-2018-8956 ntp: ntpd allows remote attackers to prevent a broadcast client from synchronizing its clock
Summary: CVE-2018-8956 ntp: ntpd allows remote attackers to prevent a broadcast client...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2018-8956
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1848590
Blocks: 1848591
TreeView+ depends on / blocked
 
Reported: 2020-06-18 15:01 UTC by Michael Kaplan
Modified: 2021-02-16 19:50 UTC (History)
3 users (show)

Fixed In Version: ntp 4.2.8p14
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2020-06-29 06:18:27 UTC
Embargoed:


Attachments (Terms of Use)

Description Michael Kaplan 2020-06-18 15:01:31 UTC
ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via spoofed mode 3 and mode 5 packets. The attacker must either be a part of the same broadcast network or control a slave in that broadcast network that can capture certain required packets on the attacker's behalf and send them to the attacker.

References:

https://arxiv.org/abs/2005.01783
https://nikhiltripathi.in/NTP_attack.pdf
https://security.netapp.com/advisory/ntap-20200518-0006/

Comment 1 Michael Kaplan 2020-06-18 15:01:49 UTC
Created ntp tracking bugs for this issue:

Affects: fedora-all [bug 1848590]

Comment 2 Huzaifa S. Sidhpurwala 2020-06-29 06:14:45 UTC
Statement:

As per the researcher this issue only affects NTP versions 4.2.8p10 through 4.2.8p13, which are not shipped with any Red Hat products, therefore they are not affected by this flaw.


Note You need to log in before you can comment on or make changes to this bug.