UBUNTU-CVE-2018-7170
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-7170
Summary:
Details: ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for CVE-2016-1549.
References: https://ubuntu.com/security/CVE-2018-7170, http://www.kb.cert.org/vuls/id/961909, http://support.ntp.org/bin/view/Main/SecurityNotice#February_2018_ntp_4_2_8p11_NTP_S, https://www.cve.org/CVERecord?id=CVE-2018-7170
Affected packages
Package
Name: ntp
Purl: pkg:deb/ubuntu/ntp@1:4.2.6.p5+dfsg-3ubuntu2.14.04.13+esm1?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
