CVE-2016-7427: Medium severity NTP ntp vulnerability
Last updated 25 August 2025
Other sources
The broadcast mode replay prevention functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (reject broadcast mode packets) via a crafted broadcast mode packet.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ntpto a version that resolves this vulnerability.Fixed in 1:4.2.8p15+dfsg-1 - Upgrade
Upgrade
ntpd (NTP)to a version that resolves this vulnerability.Fixed in 4.2.8p9
Event History
Frequently Asked Questions
What is CVE-2016-7427?
CVE-2016-7427 is a vulnerability in ntpd in NTP before 4.2.8p9 that allows remote attackers to cause a denial of service.
How does CVE-2016-7427 work?
CVE-2016-7427 works by exploiting the broadcast mode replay prevention functionality in ntpd in NTP before 4.2.8p9.
What is the severity of CVE-2016-7427?
CVE-2016-7427 has a severity rating of 4.3 (medium).
Which software versions are affected by CVE-2016-7427?
CVE-2016-7427 affects NTP versions before 4.2.8p9, 4.2.8p12+dfsg-4, and 4.2.8p15+dfsg-1 on Debian, as well as certain Ubuntu versions.
How can CVE-2016-7427 be fixed?
To fix CVE-2016-7427, users should update their NTP software to version 4.2.8p9 or later.