CVE-2016-4957: Null Pointer Dereference
Published Jul 5, 2016
·Updated
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.
Affected Software
14 affected components
NTP ntp=4.2.8-p7
NTP ntp=4.3.92
Oracle Solaris=10
Oracle Solaris=11.3
SUSE Manager Proxy=2.1
SUSE Openstack Cloud=5
Novell Suse Manager=2.1
openSUSE Leap=42.1
openSUSE openSUSE=13.2
SUSE Linux Enterprise Desktop=12-sp1
SUSE Linux Enterprise Server=11-sp2
SUSE Linux Enterprise Server=11-sp3
SUSE Linux Enterprise Server=11-sp4
SUSE Linux Enterprise Server=12-sp1
Remediation
Patch Available
Event History
Jul 5, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4957?
CVE-2016-4957 is classified as a high severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2016-4957?
To fix CVE-2016-4957, you should upgrade to NTP version 4.2.8p8 or later, or apply relevant patches provided by your vendor.
3
What types of systems are affected by CVE-2016-4957?
CVE-2016-4957 affects various systems that utilize NTP versions prior to 4.2.8p8, including several versions of Oracle Solaris and openSUSE.
4
What is the impact of exploiting CVE-2016-4957?
Exploiting CVE-2016-4957 allows remote attackers to crash the NTP daemon, leading to denial of service.
5
Was CVE-2016-4957 caused by a fix for another vulnerability?
Yes, CVE-2016-4957 exists due to an incorrect fix for CVE-2016-1547.