CVE-2009-3563: Medium severity ntp vulnerability
ntprequest.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODEPRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODEPRIVATE error responses between two NTP daemons.
Other sources
Robin Park and Dmitri Vinokurov of Alcatel-Lucent discovered a flaw in the way ntpd handles certain mode 7 packets. A remote attacker able to send specially-crafted mode 7 NTP packet with a spoofed source IP address could cause ntpd running on one host, or two ntpds running on two hosts to send error packets in loop, resulting in excessive use of CPU and disk space (via logging).
Issue is tracked by US-CERT as VU#568372.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2009-3563?
CVE-2009-3563 has a severity rating that indicates a denial of service vulnerability due to CPU and bandwidth consumption.
How do I fix CVE-2009-3563?
To fix CVE-2009-3563, upgrade to NTP versions that are patched—specifically 4.2.4p8 or later.
What software is affected by CVE-2009-3563?
CVE-2009-3563 affects various versions of the NTP daemon, specifically those prior to 4.2.4p8 and 4.2.5.
What type of attack does CVE-2009-3563 exploit?
CVE-2009-3563 exploits a vulnerability that allows remote attackers to send spoofed requests causing excessive resource consumption.
Is there a workaround for CVE-2009-3563 if I cannot upgrade?
If upgrading is not possible, restricting access to NTP services or implementing firewall rules may mitigate the risk associated with CVE-2009-3563.