USN-4563-2: NTP vulnerability
Published Apr 20, 2021
·Updated
USN-4563-1 fixed a vulnerability in NTP. This update provides the corresponding update for Ubuntu 20.04 LTS and Ubuntu 20.10. Original advisory details: It was discovered that the fix for CVE-2018-7182 introduced a NULL pointer dereference into NTP. An attacker could use this vulnerability to cause a denial of service (crash).
Affected Software
12 affected componentsFixes available
All of the following
ubuntu/ntp<1:4.2.8p12+dfsg-3ubuntu4.20.10.1
1:4.2.8p12+dfsg-3ubuntu4.20.10.1
Ubuntu Ubuntu=20.10
All of the following
ubuntu/ntpdate<1:4.2.8p12+dfsg-3ubuntu4.20.10.1
1:4.2.8p12+dfsg-3ubuntu4.20.10.1
Ubuntu Ubuntu=20.10
All of the following
ubuntu/sntp<1:4.2.8p12+dfsg-3ubuntu4.20.10.1
1:4.2.8p12+dfsg-3ubuntu4.20.10.1
Ubuntu Ubuntu=20.10
All of the following
ubuntu/ntp<1:4.2.8p12+dfsg-3ubuntu4.20.04.1
1:4.2.8p12+dfsg-3ubuntu4.20.04.1
Ubuntu Ubuntu=20.04
All of the following
ubuntu/ntpdate<1:4.2.8p12+dfsg-3ubuntu4.20.04.1
1:4.2.8p12+dfsg-3ubuntu4.20.04.1
Ubuntu Ubuntu=20.04
All of the following
ubuntu/sntp<1:4.2.8p12+dfsg-3ubuntu4.20.04.1
1:4.2.8p12+dfsg-3ubuntu4.20.04.1
Ubuntu Ubuntu=20.04
Event History
Apr 20, 2021
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this NTP vulnerability?
The vulnerability ID is USN-4563-2.
2
What is the severity of USN-4563-2?
The severity of USN-4563-2 is not specified.
3
What software is affected by USN-4563-2?
The affected software includes NTP, ntpdate, and sntp.
4
What versions of Ubuntu are affected by USN-4563-2?
The Ubuntu versions affected are 20.04 and 20.10.
5
How can I fix the USN-4563-2 vulnerability?
To fix the vulnerability, update the affected software packages to at least version 1:4.2.8p12+dfsg-3ubuntu4.20.04.1 for Ubuntu 20.04 and version 1:4.2.8p12+dfsg-3ubuntu4.20.10.1 for Ubuntu 20.10.