USN-3349-1: NTP vulnerabilities
USN-3349-1: NTP vulnerabilities Ubuntu Security Notice USN-3349-1 5th July, 2017 ntp vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in NTP. Software description ntp – Network Time Protocol daemon and utility programs Details Yihan Lian discovered that NTP incorrectly handled certain large requestdata values. A remote attacker could possibly use this issue to cause NTPto crash, resulting in a denial of service. This issue only affectedUbuntu 16.04 LTS. (CVE-2016-2519) Miroslav Lichvar discovered that NTP incorrectly handled certain spoofedaddresses when performing rate limiting. A remote attacker could possiblyuse this issue to perform a denial of service. This issue only affectedUbuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 16.10. (CVE-2016-7426) Matthew Van Gundy discovered that NTP incorrectly handled certain craftedbroadcast mode packets. [ more… ]