CVE-2016-4954: Race Condition
The processpacket function in ntpproto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstrated by triggering an incorrect leap indication.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2016-4954?
CVE-2016-4954 is classified as a denial of service vulnerability, which can severely disrupt network time synchronization services.
How do I fix CVE-2016-4954?
To mitigate CVE-2016-4954, upgrade to NTP version 4.2.8p8 or later, as this version contains fixes for the vulnerability.
What types of systems are affected by CVE-2016-4954?
CVE-2016-4954 affects various systems running vulnerable versions of NTP, including specific Siemens products and numerous Linux distributions.
Can CVE-2016-4954 be exploited remotely?
Yes, CVE-2016-4954 can be exploited by remote attackers sending spoofed packets, potentially affecting multiple source IP addresses.
What is the result of a successful exploit of CVE-2016-4954?
A successful exploit of CVE-2016-4954 can lead to a denial of service, causing the affected NTP service to malfunction or crash.