CVE-2016-2517: Input Validation
NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (prevent subsequent authentication) by leveraging knowledge of the controlkey or requestkey and sending a crafted packet to ntpd, which changes the value of trustedkey, controlkey, or requestkey. NOTE: this vulnerability exists because of a CVE-2016-2516 regression.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2517?
CVE-2016-2517 has a medium severity rating due to its potential for causing denial of service.
How do I fix CVE-2016-2517?
To fix CVE-2016-2517, update to NTP version 4.2.8p7 or later for 4.2.x, or version 4.3.92 or later for 4.3.x.
What versions of NTP are affected by CVE-2016-2517?
CVE-2016-2517 affects NTP versions prior to 4.2.8p7 and 4.3.x before 4.3.92.
What type of attack does CVE-2016-2517 enable?
CVE-2016-2517 enables remote attackers to cause a denial of service by modifying trusted keys through crafted packets.
Is CVE-2016-2517 exploitable remotely?
Yes, CVE-2016-2517 is exploitable remotely as it involves sending crafted packets to the NTP daemon.