SB2017032327 - Fedora 26 update for ntp
Published: March 23, 2017 Updated: April 24, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 7 secuirty vulnerabilities.
1) Denial of service (CVE-ID: CVE-2017-6464)
The vulnerability allows a remote authenticated attacker to cause DoS condition.The weakness exists due to improper input validation. A remote attacker can use malformed mode configuration directive to trigger memory corruption and cause the system to crash.
Successful exploitation of the vulnerability results in denial of service.
2) Buffer overflow (CVE-ID: CVE-2017-6462)
The vulnerability allows a local attacker to cause DoS condition.The weakness exists due to buffer overflow in the legacy Datum Programmable Time Server (DPTS) refclock driver in NTP. A remote attacker can send specially crafted packets, trigger memory corruption and cause the application to crash.
Successful exploitation of the vulnerability results in denial of service.
3) Configuration error (CVE-ID: CVE-2017-6463)
The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.The weakness exists in the unpeer option due to the NTP server's parsing of configuration directives. A remote attacker can submit a specially crafted message and cause the service to crash.
4) Buffer overflow (CVE-ID: CVE-2017-6458)
The vulnerability allows a remote authenticated attacker to cause DoS condition.The weakness exists due to multiple buffer overflows in the ctl_put() functions in NTP. A remote attacker can an overly long string argument, trigger memory corruption and cause the application to crash.
Successful exploitation of the vulnerability results in denial of service.
5) Out-of-bounds write (CVE-ID: CVE-2017-6451)
The vulnerability allows a local attacker to execute arbitrary code on the target system.The weakness exists due to improper handling of the return value of the snprintf function by the mx4200_send function in the legacy MX4200 refclock in NTP. A local attacker can trigger out-of-bounds memory write and execute arbitrary code with root privileges.
Successful exploitation of the vulnerability may result in system compromise.
6) Stack-based buffer overflow (CVE-ID: CVE-2017-6460)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.The weakness exists in the reslist() function in ntpq due to stack-based buffer overflow triggered by a malicious ntpd server when ntpq requests the restriction list from the server. A remote attacker can trigger memory corruption and execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
7) Input validation error (CVE-ID: CVE-2016-9042)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.
Remediation
Install update from vendor's website.