CVE-2013-5211: Input Validation
Published Jan 2, 2014
·Updated
The monlist feature in ntprequest.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQMONGETLIST or (2) REQMONGETLIST1 requests, as exploited in the wild in December 2013.
Affected Software
32 affected components
openSUSE openSUSE=11.4
NTP ntp<4.2.7
NTP ntp=4.2.7
NTP ntp=4.2.7-p0
NTP ntp=4.2.7-p1
NTP ntp=4.2.7-p10
NTP ntp=4.2.7-p11
NTP ntp=4.2.7-p12
NTP ntp=4.2.7-p13
NTP ntp=4.2.7-p14
NTP ntp=4.2.7-p15
NTP ntp=4.2.7-p16
NTP ntp=4.2.7-p17
NTP ntp=4.2.7-p18
NTP ntp=4.2.7-p19
NTP ntp=4.2.7-p2
NTP ntp=4.2.7-p20
NTP ntp=4.2.7-p21
NTP ntp=4.2.7-p22
NTP ntp=4.2.7-p23
NTP ntp=4.2.7-p24
NTP ntp=4.2.7-p25
NTP ntp=4.2.7-p3
NTP ntp=4.2.7-p4
NTP ntp=4.2.7-p5
NTP ntp=4.2.7-p6
NTP ntp=4.2.7-p7
NTP ntp=4.2.7-p8
NTP ntp=4.2.7-p9
Oracle Linux=6
Oracle Linux=7
NTP ntp=4.2.7
Remediation
Event History
Jan 2, 2014
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5211?
CVE-2013-5211 has a severity rating of medium due to its potential for denial of service attacks.
2
How do I fix CVE-2013-5211?
To fix CVE-2013-5211, upgrade to NTP version 4.2.7p26 or later.
3
What kind of attack does CVE-2013-5211 enable?
CVE-2013-5211 enables remote attackers to execute traffic amplification denial of service attacks.
4
Which systems are affected by CVE-2013-5211?
CVE-2013-5211 affects NTP versions prior to 4.2.7p26 and certain versions of openSUSE and Oracle Linux.
5
Is CVE-2013-5211 actively exploited?
Yes, CVE-2013-5211 was actively exploited in the wild starting in December 2013.