UBUNTU-CVE-2016-1550
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-1550
UBUNTU-CVE-2016-1550
Published: 29 Apr 2016Last Modified: 4 Feb 2026
Upstream:
Aliases:
Summary:
Details: An exploitable vulnerability exists in the message authentication functionality of libntp in ntp 4.2.8p4 and NTPSec a5fb34b9cc89b92a8fef2f459004865c93bb7f92. An attacker can send a series of crafted messages to attempt to recover the message digest key.
References: https://ubuntu.com/security/CVE-2016-1550, http://support.ntp.org/bin/view/Main/SecurityNotice#April_2016_NTP_4_2_8p7_Security, http://www.talosintel.com/reports/TALOS-2016-0084/, https://ubuntu.com/security/notices/USN-3096-1, https://www.cve.org/CVERecord?id=CVE-2016-1550
Affected packages
Package
Name: ntp
Purl: pkg:deb/ubuntu/ntp@1:4.2.6.p5+dfsg-3ubuntu2.14.04.10?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -1:4.2.6.p5+dfsg-3ubuntu2.14.04.10
Affected versions
1:4.2.6.p5+dfsg-3ubuntu2
1:4.2.6.p5+dfsg-3ubuntu2.14.04.1
1:4.2.6.p5+dfsg-3ubuntu2.14.04.2
1:4.2.6.p5+dfsg-3ubuntu2.14.04.3
1:4.2.6.p5+dfsg-3ubuntu2.14.04.5
1:4.2.6.p5+dfsg-3ubuntu2.14.04.6
1:4.2.6.p5+dfsg-3ubuntu2.14.04.7
1:4.2.6.p5+dfsg-3ubuntu2.14.04.8
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
